CVE-2019-5591
CVE-2019-5591: 1 tracked advisory record across Fortinet. CISA KEV listed; exploitation observed. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Fortinet
1 advisory- Advisory severityMedium5.0
Medium [CVE-2019-5591] Fortinet FortiOS: Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server
CVE-2019-5591Source published Source updated
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server. Affected product named by the advisory: Fortinet FortiOS.
- Affected products in this advisory
- FortiOS
- Source-reported affected versions
- FortiOS 6.2.0 and below.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- For users running versions 6.0.3 to 6.2.0, enabling the CLI option that checks for LDAP server identity entirely prevents the issue.
- This option can be enabled only if secure and ca-cert of the LDAP server are set.
- config user ldapedit ldap-serverset ca-cert <ldap-server-certificate>set secure ldaps set server-identity-check enableFortiOS 6.2.1 and above have server-identity-check enabled by default, when installed from scratch.However, for compatibility reasons, the value of server-identity-check is kept unchanged throughout firmware upgrading.
- In other words, upgrading from 6.0.3 - 6.2.0 to 6.2.1 and above does not suffice to thwart the issue: server-identity-check must be enabled (prior the upgrade of after, indifferently).
Android app · Google Play
Monitor future Fortinet CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.