Loading
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
Use CWE-732, Fortinet vendor hub and Fortiadc product page to widen CVE-2018-13374 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-37933, CVE-2023-50178 and CVE-2025-49813 for nearby disclosures in the same product family.