> LDAP Clear-text credentials retrievable with IP modification
[DATE: 08/04/2025 07:00]
[LANGUAGE: EN]
CVSSv3 Score:
2.1
An insufficiently protected credentials [CWE-522] vulnerability in FortiOS may allow a privileged authenticated attacker to retrieve LDAP credentials via modifying the LDAP server IP address in the FortiOS configuration to point to a malicious attacker-controlled server.
Revised on 2025-10-21 00:00:00