Medium [CVE-2019-5591] Fortinet FortiOS: Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server
This medium-severity Fortinet advisory covers CVE-2019-5591 affecting Fortinet FortiOS.
Android app · Google Play
Monitor future Fortinet CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
Affected product named by the advisory: Fortinet FortiOS.
CISA Known Exploited Vulnerability
- Listed:
- Nov 3, 2021 · federal remediation due May 3, 2022
- Required action:
- Apply updates per vendor instructions.
- Ransomware use:
- Known
KEV is a prioritization signal from CISA — remediation detail still comes from the vendor advisory.
- Fortinet FortiOS FortiOS 6.2.0 and below.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- For users running versions 6.0.3 to 6.2.0, enabling the CLI option that checks for LDAP server identity entirely prevents the issue.
- This option can be enabled only if secure and ca-cert of the LDAP server are set.
- config user ldapedit ldap-serverset ca-cert <ldap-server-certificate>set secure ldaps set server-identity-check enableFortiOS 6.2.1 and above have server-identity-check enabled by default, when installed from scratch.However, for compatibility reasons, the value of server-identity-check is kept unchanged throughout firmware upgrading.
- In other words, upgrading from 6.0.3 - 6.2.0 to 6.2.1 and above does not suffice to thwart the issue: server-identity-check must be enabled (prior the upgrade of after, indifferently).
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.