{"id":"CVE-2018-13374","vendor_project":"Fortinet","product":"FortiOS and FortiADC","vulnerability_name":"Fortinet FortiOS and FortiADC Improper Access Control Vulnerability","date_added":"2022-09-08","due_date":"2022-09-29","known_ransomware_use":"Known","short_description":"Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.","required_action":"Apply updates per vendor instructions.","cwes":"CWE-732","cvss_version":"3.1","cvss_severity":"MEDIUM","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","nvd_published":"2019-01-22","nvd_status":"Analyzed","epss":0.37832,"epss_percentile":0.98481,"cvss_score":4.3,"days_published_to_kev":1325,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2018-13374","by":"CyberMax"}