Skip to content
COOEY

EXPOSURES › CVE-2019-5591

CVE-2019-5591

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-5591 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wilddefault-credsunpatched

Fortinet FortiOS default configurations allowed unauthenticated attackers on the same subnet to impersonate an LDAP server and intercept sensitive information.

A default configuration vulnerability in Fortinet FortiOS enabled an unauthenticated attacker on the same subnet to impersonate an LDAP server and intercept sensitive information. DIB organizations must ensure FortiOS is patched to the latest version and default configurations are hardened to prevent similar exposures. This failure highlights the risk of relying on default settings without proper hardening.

Shame score — Default configuration vulnerabilities are avoidable and expose sensitive data to interception, indicating a lack of proper hardening and reliance on insecure defaults.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -1.00
"…"
app.opencve.io ↗ severe-fallout -1.00
"…"
www.cvefind.com ↗ severe-fallout -1.00
"…"
xposedornot.com ↗ severe-fallout -1.00
"…"
cvefeed.io ↗ severe-fallout -1.00
"…"
securityonline.info ↗ severe-fallout -1.00
"…"
www.hipaajournal.com ↗ severe-fallout -1.00
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.