Skip to content
VulniPulse
Medium5.0Fortinet Exploited CISA KEV

Medium [CVE-2019-5591] Fortinet FortiOS: Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server

This medium-severity Fortinet advisory covers CVE-2019-5591 affecting Fortinet FortiOS.

CVE-2019-5591 Published Aug 14, 2020Updated by vendor Aug 15, 2026
Affected products & platforms
FortinetFortiGateFirewallFortiOS
Open vendor advisory

Android app · Google Play

Monitor future Fortinet CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

Affected product named by the advisory: Fortinet FortiOS.

CISA Known Exploited Vulnerability

Listed:
Nov 3, 2021 · federal remediation due May 3, 2022
Required action:
Apply updates per vendor instructions.
Ransomware use:
Known

KEV is a prioritization signal from CISA — remediation detail still comes from the vendor advisory.

Affected versions
  • Fortinet FortiOS FortiOS 6.2.0 and below.

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • For users running versions 6.0.3 to 6.2.0, enabling the CLI option that checks for LDAP server identity entirely prevents the issue.
  • This option can be enabled only if secure and ca-cert of the LDAP server are set.
  • config user ldapedit ldap-serverset ca-cert <ldap-server-certificate>set secure ldaps set server-identity-check enableFortiOS 6.2.1 and above have server-identity-check enabled by default, when installed from scratch.However, for compatibility reasons, the value of server-identity-check is kept unchanged throughout firmware upgrading.
  • In other words, upgrading from 6.0.3 - 6.2.0 to 6.2.1 and above does not suffice to thwart the issue: server-identity-check must be enabled (prior the upgrade of after, indifferently).

Official advisory · high-confidence parse· fetched 2 hours ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.