PoC Index

CVE-2018-13374

KEV RANSOMWAREMEDIUM 4.3EPSS 37.8%

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
37.83% chance of exploitation in the next 30 days, 98th percentile
CISA KEV
added 2022-09-08, used in ransomware campaigns
Published
2019-01-22
Updated
2026-08-13

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related