Junglewise Threat Intelligence

CVE-2018-13374: Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

CVE-2018-13374 · Severity: critical · CVSS 4.3 · Exploited in the wild · Published 2022-09-08

Technologies: Fortinet FortiOS, Fortinet FortiADC. Vendors: Fortinet.

Executive brief

An improper access control vulnerability in Fortinet FortiOS and FortiADC allows an authenticated attacker to obtain configured LDAP server login credentials. This is achieved by redirecting an LDAP server connectivity test request to a rogue LDAP server.

Affected products

  • Fortinet FortiOS <= 5.6.7, 6.0.0 to 6.0.2
  • Fortinet FortiADC 5.4.0 to 5.4.4, 6.0.0 to 6.0.1, 6.1.0

Timeline

  • 2019-01-23: other: Exploit-DB reference added to record
  • 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-09-08: disclosed: NVD publication date

Related threats