Skip to content
COOEY

EXPOSURES › CVE-2018-13374

CVE-2018-13374

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-09-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-13374 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

Fortinet FortiOS and FortiADC allowed attackers to steal LDAP credentials by redirecting connectivity test requests to a rogue server.

This improper access control flaw exposed LDAP server login credentials, enabling attackers to impersonate legitimate users or escalate privileges. DIB organizations must ensure LDAP configurations are protected from redirection attacks and verify vendor patching timelines for critical infrastructure.

Shame score — A critical, actively exploited vulnerability in core Fortinet products that directly enabled credential theft and ransomware-linked attacks, reflecting a severe avoidable failure in access control design.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.