Vulnerability record · CVE-2019-5591 · published 14 August 2020
CVE-2019-5591: FortiOS default configuration allows LDAP server impersonation
Fortinet · Fortios
FortiOS ships with a default configuration that lets an unauthenticated attacker on the same subnet impersonate the LDAP server. Because the device accepts the impersonated server without authentication, sensitive information sent to LDAP can be intercepted. The flaw is a missing-authentication issue in a critical function, and it is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityIt is in CISA KEV with known ransomware use and a high EPSS percentile, though the CVSS score is only medium and the attack requires adjacency to the target subnet.
What it is
FortiOS ships with a default configuration that lets an unauthenticated attacker on the same subnet impersonate the LDAP server. Because the device accepts the impersonated server without authentication, sensitive information sent to LDAP can be intercepted. The flaw is a missing-authentication issue in a critical function, and it is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker on the same network segment can capture sensitive information that the FortiGate sends to its LDAP server, such as credentials or directory data. There is no integrity or availability impact; the loss is confidentiality only.
Attack surface
Reachable from an adjacent network segment (AV:A) with no privileges and no user interaction required (PR:N/UI:N). The attacker must already be positioned on the same subnet as the affected device.
Exploitation
CISA added it to the KEV catalog on 2021-11-03 with a 2022-05-03 remediation due date and flags known ransomware campaign use. EPSS gives a 30-day exploitation probability of about 18.4 percent (97th percentile), and the vendor advisory is tagged Mitigation and Vendor Advisory.
What to do
- Apply the FortiOS updates referenced in Fortinet advisory FG-IR-19-037 as the first action.
- Do not rely on the default LDAP configuration; explicitly configure and validate the LDAP server identity on each FortiGate.
- Restrict management and LDAP traffic to trusted internal segments and isolate FortiGate devices from untrusted adjacent hosts.
- Follow the vendor mitigation guidance in FG-IR-19-037 if patching cannot be done immediately.
- Track remediation against the CISA KEV due date of 2022-05-03.
Detection
- Monitor for rogue or unexpected LDAP servers answering on the same subnet as FortiGate devices.
- Alert on FortiGate LDAP traffic to hosts that are not the approved directory server.
- Review FortiGate configuration for default or unvalidated LDAP server settings.
- Hunt for signs of credential or directory data exposure tied to FortiGate LDAP communications.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-5591 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Fortinet FortiOS Default Configuration Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.fortiguard.com/psirt/FG-IR-19-037 | MitigationVendor Advisory |
| https://www.fortiguard.com/psirt/FG-IR-19-037 | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-5591 | US Government Resource |
Track CVE-2019-5591 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-5591), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.