VYPR
Medium severity4.3CISA KEVNVD Advisory· Published Jan 22, 2019· Updated Aug 13, 2026

CVE-2018-13374

CVE-2018-13374

Description

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*range: >=5.4.0,<5.4.5
    • cpe:2.3:a:fortinet:fortiadc:6.1.0:*:*:*:*:*:*:*
  • Fortinet/Fortios2 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: <6.0.3
    • (no CPE)range: 6.0.2, 5.6.7 and before
  • Range: 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4
  • Fortinet/Fortinetcpe-rescue
    Range: FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.