CVE-2018-13374: Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

Medium severity, CVSS 4.3. Actively exploited: in CISA KEV since 2022-09-08. EPSS: 38.1% chance of exploitation in the next 30 days.

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

Affected products

  • Fortinet FortiADC: from 5.4.0, before 5.4.5 (fixed in 5.4.5); from 6.0.0, before 6.0.2 (fixed in 6.0.2); version 6.1.0 only
  • Fortinet FortiOS: before 6.0.3 (fixed in 6.0.3)

Published 2019-01-22. Last modified 2026-10-01.