CVSS v3
6.5
MEDIUM
EPSS Score
51.6%
exploit probability
CISA KEV
Yes
known exploited
Exploitation
—
SSVC status
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
Yes. CVE-2019-5591 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 5/3/2022.
CVE-2019-5591 has a CVSS v3 base score of 6.5 (MEDIUM severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).