CVE-2018-13374 is a vulnerability in Fortinet Fortios
Published on January 22, 2019
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
Known Exploited Vulnerability
This Fortinet FortiOS and FortiADC Improper Access Control Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Fortinet FortiOS and FortiADC contain an improper access control vulnerability which allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.
The following remediation steps are recommended / required by September 29, 2022: Apply updates per vendor instructions.
CVE-2018-13374 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. It has an exploitability score of 2.8 out of four. The potential impact of an exploit of this vulnerability is considered to be very high.
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. When a resource is given a permissions setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution or sensitive user data.
Products Associated with CVE-2018-13374
You can be notified by stack.watch whenever vulnerabilities like CVE-2018-13374 are published in these products:
What versions of Fortios are vulnerable to CVE-2018-13374?
- Fortinet Fortios Up to Version 5.6.7
- Fortinet Fortios Version 6.0.0 through 6.0.2