CVE-2018-13378: Infoleak
Published Apr 17, 2019
·Updated
An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source code.
Affected Software
1 affected component
Fortinet FortiSIEM<=5.2.0
Event History
Apr 17, 2019
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-13378?
CVE-2018-13378 is an information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions that exposes the LDAP server plaintext password via the HTML source code.
2
How does CVE-2018-13378 affect Fortinet FortiSIEM?
CVE-2018-13378 affects Fortinet FortiSIEM 5.2.0 and below versions, exposing the LDAP server plaintext password in the HTML source code.
3
What is the severity of CVE-2018-13378?
The severity of CVE-2018-13378 is high, with a severity score of 7.2.
4
How can I fix CVE-2018-13378?
To fix CVE-2018-13378, Fortinet users should update FortiSIEM to a version above 5.2.0.
5
Where can I find more information about CVE-2018-13378?
You can find more information about CVE-2018-13378 in Fortinet's advisory FG-IR-18-382.