CVE-2018-13374
בינונית 4.3 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
מדדים
- CVSS 3.1
-
4.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 38% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-732
מוצרים מושפעים
fortinet: fortiadc; fortinet: fortios
קישורים
- https://fortiguard.com/advisory/FG-IR-18-157 Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-18-157 Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource