CVE-2018-13374
CVE-2018-13374 is a medium-severity vulnerability in Fortinet Fortiadc with a CVSS 3.x base score of 4.3. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2022-09-08). The underlying weakness is classified as CWE-732.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- CVSS v2: 4.0
- EPSS exploit prediction: 38% (98th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2022-09-08)
- EU (EUVD) id: EUVD-2018-5318
- EU exploitation: Flagged exploited in the ENISA EU Vulnerability Database (since 2022-09-08)
- Weakness: CWE-732
- Affected product: Fortinet Fortiadc
- Published:
- Last modified:
Description
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
Frequently asked questions
- What is CVE-2018-13374?
- A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
- How severe is CVE-2018-13374?
- CVE-2018-13374 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2018-13374 being actively exploited?
- Yes. CVE-2018-13374 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2022-09-08, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2018-13374?
- CVE-2018-13374 primarily affects Fortinet Fortiadc. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2018-13374?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- Does CVE-2018-13374 have an EU (EUVD) identifier?
- Yes. CVE-2018-13374 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2018-5318. It is also flagged as exploited in the EUVD (since 2022-09-08).
- When was CVE-2018-13374 published?
- CVE-2018-13374 was published on 2019-01-22 and last updated on 2026-08-13.
References
- https://fortiguard.com/advisory/FG-IR-18-157
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13374
Affected products (3)
- cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortiadc:6.1.0:*:*:*:*:*:*:*
- cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
More vulnerabilities in Fortinet Fortiadc
- CVE-2023-37933 — High (CVSS 8.8): An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in…
- CVE-2022-39947 — High (CVSS 8.8): A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC…
- CVE-2022-38374 — High (CVSS 8.8): A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 -…
- CVE-2023-26205 — High (CVSS 8.1): An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all…
- CVE-2022-35851 — High (CVSS 8.0): An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface…
- CVE-2023-25607 — High (CVSS 7.8): An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ]…
All CVEs affecting Fortinet Fortiadc →
Other CWE-732 (Incorrect Permission Assignment for Critical Resource) vulnerabilities
- CVE-2026-9508 — Critical (CVSS 10.0): Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow…
- CVE-2025-14988 — Critical (CVSS 10.0): A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain…
- CVE-2025-69426 — Critical (CVSS 10.0): The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating…
- CVE-2025-12004 — Critical (CVSS 10.0): Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown…
- CVE-2014-125121 — Critical (CVSS 10.0): Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation…
- CVE-2025-46093 — Critical (CVSS 9.9): LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to…
Browse all CWE-732 (Incorrect Permission Assignment for Critical Resource) vulnerabilities →