First published: Wed Apr 17 2019(Updated: )
An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source code.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSIEM | <=5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13378 is an information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions that exposes the LDAP server plaintext password via the HTML source code.
CVE-2018-13378 affects Fortinet FortiSIEM 5.2.0 and below versions, exposing the LDAP server plaintext password in the HTML source code.
The severity of CVE-2018-13378 is high, with a severity score of 7.2.
To fix CVE-2018-13378, Fortinet users should update FortiSIEM to a version above 5.2.0.
You can find more information about CVE-2018-13378 in Fortinet's advisory FG-IR-18-382.