← Back to browse · API

CVE-2018-13374

Severity
MEDIUM
CVSS
4.3
EPSS
0.38088
Risk score
55.53
CISA KEV
Yes
PoC
No
Published
2022-09-08
Modified
2022-09-08
First seen
2026-08-07
Aliases
EUVD-2018-5318, GHSA-RPMQ-Q4MW-PC44
Products
Fortinet:FortiOS and FortiADC, Fortinet:Fortinet FortiOS, fortiADC FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4
Sources
euvd EUVD-2018-5318
cisa.gov CVE-2018-13374

Description

Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.

References