Back

MEDIUM KEV Used in ransomware campaigns

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one

Published Jan 22, 2019 ·Due Sep 29, 2022

Description

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (6)
  1. CISA ADP
    • SSVC technical impact changed from partial to total
  2. CISA ADP
    • SSVC technical impact changed from total to partial
  3. CISA ADP
    • SSVC technical impact changed from partial to total
  4. CISA ADP
    • SSVC technical impact changed from total to partial
  5. CISA ADP
    • SSVC technical impact changed from partial to total
  6. CISA ADP
    • SSVC technical impact changed from total to partial
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fortinet
Published Jan 22, 2019
Updated Oct 1, 2026
Reserved Jul 6, 2018
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Analyzed
Modified Aug 13, 2026
Red Hat
Severity n/a
Public date n/a