Vulnerability Description
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiadc | >= 5.4.0, < 5.4.5 |
| Fortinet | Fortios | < 6.0.3 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/advisory/FG-IR-18-157Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-18-157Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-US Government Resource
FAQ
What is CVE-2018-13374?
CVE-2018-13374 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGat...
How severe is CVE-2018-13374?
CVE-2018-13374 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-13374?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortiadc, Fortinet Fortios.