CVE-2018-13374
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
MEDIUM · CVSS 4.3
⚠ CISA KEV
EPSS 0.03367
Ransomware: known
Act now
- Listed on CISA KEV (known exploited in the wild)
- Linked to known ransomware campaigns
- SSVC exploitation status: active
- Public exploit or PoC is available
Sigma rules0
YARA rules0