MEDIUM

CVE-2019-5591

Fortinet Fortios 2020-08-14 CVSS v3.1
CVSS
6.5
KEV

Description

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

Summary dbcve.org

FortiOS contains a default configuration vulnerability where the LDAP server authentication does not properly validate server certificates or uses insecure settings. An unauthenticated attacker on the same subnet can perform a man-in-the-middle attack to impersonate the LDAP server and intercept sensitive authentication credentials.

Mitigation

Change the default LDAP configuration to enforce LDAPS (LDAP over SSL/TLS) with certificate validation, or implement mutual TLS authentication to prevent LDAP server impersonation.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

18.42%
Probability of exploitation in next 30 days
97.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE