CVE-2018-13374

Fortinet FortiOS and FortiADC: Improper Access Control

As of , CVE-2018-13374 in Fortinet FortiOS and FortiADC is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 8 September 2022
US federal deadline
29 September 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.38Higher than 98% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.07 on 8 September 2022EPSS on the day CISA listed it.
Public exploit
1 Exploit-DB entry (1 verified)
Fix
Vendor advice: www.fortiguard.comLinks below, from CISA's entry.

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.

CISA's description

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

The CVE record's description, from fortinet

CVE published
22 January 2019
Assigned by
fortinet
CVSS
4.3 Medium (CVSS 3.1, from the CNA)
CWE-732
Incorrect Permission Assignment for Critical Resource
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. Exploit-DB published an exploit (EDB-ID 46171).
  2. The CVE record was published.
  3. CISA added it to its list of exploited vulnerabilities.
  4. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Read further