ZeroHour

CVE-2018-13374

KEV ransomwaremass

Improper Access Control in Fortinet FortiOS and FortiADC Exposes LDAP Credentials

CISA: Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

CVSS 3.1
4.3 medium
EPSS
38%p98
Published
()
KEV added
AI analysis

Fortinet FortiOS (FortiGate) and FortiADC contain an improper access control flaw (CWE-732) related to the LDAP server connectivity test feature. An attacker can point an LDAP connectivity test request to a rogue LDAP server under their control, causing FortiGate to transmit its configured LDAP server login credentials to that server. Capturing these credentials yields valid LDAP bind credentials — typically Active Directory usernames and passwords — that can be reused for further access into the victim's directory environment. Organizations running affected FortiGate (FortiOS) or FortiADC appliances with LDAP authentication configured are exposed; the available data does not specify exact affected version ranges. The flaw is listed in CISA's KEV (added 2022-09-08) with known ransomware use, and EPSS assigns a 37.8% probability of exploitation within 30 days (98th percentile).

What to do: Apply updates per Fortinet's vendor instructions on both FortiOS and FortiADC, as required by the CISA KEV listing. After patching, rotate the LDAP bind credentials configured on FortiGate in case they were captured, and review logs for LDAP connectivity test requests directed at unexpected or unauthorized LDAP servers.

Affected
Fortinet FortiOS (FortiGate)
Fortinet FortiADC
Estimated exposure
mass≈1M+ installations (FortiGate is among the most widely deployed firewall lines, with hundreds of thousands of Fortinet devices visible in public internet scans) — Fortinet has shipped millions of FortiGate units and public scans routinely show hundreds of thousands of exposed Fortinet devices, though only deployments using LDAP with reachable connectivity-test functionality are actually vulnerable.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

CISA Known Exploited Vulnerability
Affected
Fortinet FortiOS and FortiADC
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
fortinet
Products
fortiadc, fortios
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news