MEDIUM
CVE-2019-5591
CVSS
6.5
KEV
Description
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
Summary dbcve.org
FortiOS contains a default configuration vulnerability where the LDAP server authentication does not properly validate server certificates or uses insecure settings. An unauthenticated attacker on the same subnet can perform a man-in-the-middle attack to impersonate the LDAP server and intercept sensitive authentication credentials.
Mitigation
Change the default LDAP configuration to enforce LDAPS (LDAP over SSL/TLS) with certificate validation, or implement mutual TLS authentication to prevent LDAP server impersonation.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
18.42%
Probability of exploitation in next 30 days
97.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.