---
id: CVE-2018-13374
title: >-
  A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before,
  FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the
  LDAP server login credentials configured in FortiGate via pointing a LDAP
  server connecti…
summary: >-
  A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before,
  FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the
  LDAP server login credentials configured in FortiGate via pointing a LDAP
  server connecti…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-732
  - CWE-732
vendor: fortinet
product: fortiadc
affected:
  - 'fortiadc >= 5.4.0, < 5.4.5'
  - 'fortiadc >= 6.0.0, < 6.0.2'
  - fortiadc = 6.1.0
  - fortios < 6.0.3
patched:
  - fortiadc 6.0.2
  - fortios 6.0.3
published: '2019-01-22'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-13374'
references:
  - url: 'https://fortiguard.com/advisory/FG-IR-18-157'
    label: psirt@fortinet.com
  - url: 'https://fortiguard.com/advisory/FG-IR-18-157'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13374
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.37832
epssPercentile: 0.98523
kev: true
kevDateAdded: '2022-09-08'
kevDueDate: '2022-09-29'
kevRansomware: true
exploited: true
exploitAvailable: true
ingestedAt: '2026-08-13T06:00:54.635Z'
exploits:
  exploitdb: true
  github: 1
  githubRepos:
    - 'https://github.com/Justjeff211/conti-ransomware-writeup'
  checkedAt: '2026-09-21T15:23:39.464Z'
---

## Overview

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

## Affected

- `fortiadc >= 5.4.0, < 5.4.5`
- `fortiadc >= 6.0.0, < 6.0.2`
- `fortiadc = 6.1.0`
- `fortios < 6.0.3`

## Remediation

Upgrade past the affected range:

- `fortiadc 6.0.2`
- `fortios 6.0.3`
