CVE-2018-13374
KEV RANSOMWAREMEDIUM 4.3EPSS 37.8%
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
- CVSS v3.1
- 4.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - CVSS v3.1
- 4.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - CVSS v2.0
- 4.0 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N - EPSS
- 37.83% chance of exploitation in the next 30 days, 98th percentile
- CISA KEV
- added 2022-09-08, used in ransomware campaigns
- Published
- 2019-01-22
- Updated
- 2026-08-13
Proof-of-concept exploits (1)
- juliourena/plaintext176★ · 2026-05-26