Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
Fortinet · FortiOS and FortiADC
Date added (CISA)
2022-09-08
Remediation due
2022-09-29
Known ransomware use
Yes
Remediation priority
P1 — known ransomware use · past CISA due date
Description
Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.