SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-13374

Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

KEVMEDIUM 4.3EPSS 37.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 29 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
37.83% probability · 98th percentile
CISA KEV
Listed 8 September 2022 · due 29 September 2022 · used in ransomware campaigns
Weakness
CWE-732
Affected
fortinet/fortiadc · fortinet/fortios
Source
psirt@fortinet.com

CISA notes

Apply updates per vendor instructions. https://www.fortiguard.com/psirt/FG-IR-18-157; https://nvd.nist.gov/vuln/detail/CVE-2018-13374

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.