CVE-2018-13374
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 29 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 37.83% probability · 98th percentile
- CISA KEV
- Listed 8 September 2022 · due 29 September 2022 · used in ransomware campaigns
- Weakness
- CWE-732
- Affected
- fortinet/fortiadc · fortinet/fortios
- Source
- psirt@fortinet.com
CISA notes
Apply updates per vendor instructions. https://www.fortiguard.com/psirt/FG-IR-18-157; https://nvd.nist.gov/vuln/detail/CVE-2018-13374
References
- https://fortiguard.com/advisory/FG-IR-18-157Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-18-157Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13374US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.