CISA Known Exploited Vulnerability

CVE-2018-13374 Ransomware

Fortinet · FortiOS and FortiADC

Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

Date added
BOD 22-01 due date
CWE CWE-732
Ransomware Known

CISA description

Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.

Required action

Apply updates per vendor instructions.