CVE-2018-13378

Severity
7.2HIGH
EPSS
0.3%
top 43.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 17
Latest updateMay 14

Description

An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source code.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

CVEListV5fortinet_fortisiemFortiSIEM 5.2.0

🔴Vulnerability Details

2
GHSA
GHSA-8r6q-h646-7gph: An information disclosure vulnerability in Fortinet FortiSIEM 52022-05-14
CVEList
CVE-2018-13378: An information disclosure vulnerability in Fortinet FortiSIEM 52019-04-17

📋Vendor Advisories

1
Fortinet
An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext...2019-04-17