Vulnerability record · CVE-2018-13374 · published 22 January 2019
CVE-2018-13374: FortiOS and FortiADC access control flaw exposes LDAP credentials
Fortinet · Fortiadc
FortiOS (6.0.2, 5.6.7 and earlier) and FortiADC (6.1.0, 6.0.0-6.0.1, 5.4.0-5.4.4) contain an improper access control flaw. An attacker can redirect an LDAP server connectivity test to a rogue LDAP server and capture the LDAP login credentials configured on the FortiGate. The leaked credentials are sensitive directory-service secrets that can enable further access.
Description
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Automated analysis
high priorityThe flaw leaks directory credentials and is in CISA KEV with known ransomware use, though the CVSS base score is only 4.3 and exploitation requires low privileges and redirection of the LDAP test.
What it is
FortiOS (6.0.2, 5.6.7 and earlier) and FortiADC (6.1.0, 6.0.0-6.0.1, 5.4.0-5.4.4) contain an improper access control flaw. An attacker can redirect an LDAP server connectivity test to a rogue LDAP server and capture the LDAP login credentials configured on the FortiGate. The leaked credentials are sensitive directory-service secrets that can enable further access.
Impact
An attacker obtains the LDAP server login credentials configured in FortiGate, giving them valid directory credentials that can be reused against the LDAP service or related systems.
Attack surface
Reached over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N). The attacker must be able to influence or redirect the LDAP connectivity test to a rogue LDAP server.
Exploitation
Listed in CISA KEV (added 2022-09-08) with known ransomware campaign use, and EPSS 30-day probability 0.378 (98.5th percentile), indicating observed exploitation activity. No public exploit details are provided in the record.
What to do
- Apply the Fortinet updates referenced in advisory FG-IR-18-157 for affected FortiOS and FortiADC versions.
- Restrict management and LDAP connectivity-test functionality to trusted administrative networks.
- Rotate LDAP bind credentials configured on FortiGate and FortiADC devices that may have been exposed.
- Monitor and restrict outbound LDAP traffic so connectivity tests cannot reach rogue LDAP servers.
Detection
- Review FortiGate/FortiADC logs for LDAP connectivity-test actions directed to unexpected or external LDAP server addresses.
- Alert on outbound LDAP connections from Fortinet devices to non-approved LDAP endpoints.
- Audit LDAP bind credential use for authentication from unexpected source IPs or at unusual times.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-13374 to the Known Exploited Vulnerabilities catalog on 8 September 2022 as "Fortinet FortiOS and FortiADC Improper Access Control Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 29 September 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/advisory/FG-IR-18-157 | Vendor Advisory |
| https://fortiguard.com/advisory/FG-IR-18-157 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13374 | US Government Resource |
Track CVE-2018-13374 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-13374), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.