EXPOSURES › CVE-2019-5591
CVE-2019-5591
HIGH ⌖ ON CISA KEV · EXPLOITEDFortinet FortiOS default configurations allowed unauthenticated attackers on the same subnet to impersonate an LDAP server and intercept sensitive information.
A default configuration vulnerability in Fortinet FortiOS enabled an unauthenticated attacker on the same subnet to impersonate an LDAP server and intercept sensitive information. DIB organizations must ensure FortiOS is patched to the latest version and default configurations are hardened to prevent similar exposures. This failure highlights the risk of relying on default settings without proper hardening.
Shame score — Default configuration vulnerabilities are avoidable and expose sensitive data to interception, indicating a lack of proper hardening and reliance on insecure defaults.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.