CVE-2018-13374 PUBLISHED KEV CVSS 8.800000190734863 HIGH

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

EPSS 3.78% · 88.0th percentile

Risk Scores

CVSS v3.0
8.800000190734863
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
3.78%
88.0th percentile

Affected Products

VendorProductVersions
fortinetfortiadc5.4.0, 6.0.0, 6.1.0
fortinetfortios0

Timeline

References

Open in Interactive Console →