CVE-2019-5591 is a default configuration vulnerability in Fortinet FortiOS involving improper LDAP server certificate validation. An unauthenticated attacker on the same subnet can impersonate an LDAP server and potentially intercept sensitive information, including authentication credentials, through a man-in-the-middle attack. Identified affected versions include FortiOS 5.4.6–5.4.12, 5.6.3–5.6.7, 6.0.0–6.0.3, and 6.2.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof of Concept (PoC) exploit for CVE-2019-5591, targeting Fortinet FortiOS versions 6.0.3 through 6.2.0. The exploit consists of a single Python script, 'ldap_honeypot.py', which implements a fake LDAP server (honeypot) that listens on TCP port 389. When a vulnerable FortiGate device attempts to authenticate via LDAP, the honeypot captures the credentials (usernames and passwords) sent in BIND requests. The script parses incoming LDAP requests, logs the captured credentials, and provides session summaries. The README.md provides context, affected versions, and a demonstration of the exploit in action. There are no hardcoded external endpoints; the exploit is designed to be run on the attacker's local subnet to intercept traffic from vulnerable devices. The repository is structured simply, with the main exploit logic contained in a single Python file, and is intended for demonstration and research purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Fortinet FortiOS vulnerability involving interception of sensitive information, cited among vulnerabilities used by Iranian-linked threat groups for initial access.
A default-configuration vulnerability affecting Fortinet FortiOS 6.2.0 and earlier. An unauthenticated attacker on the same subnet may impersonate the LDAP server to intercept sensitive information.
CVE-2019-5591 is a vulnerability in FortiOS that allows an unauthenticated attacker to perform a man-in-the-middle (MitM) attack due to improper configuration of the FortiGate device, particularly when LDAP authentication is enabled. This can allow attackers to intercept or manipulate network traffic.
A vulnerability in FortiOS where improper LDAP server certificate validation allows attackers on the same subnet to perform man-in-the-middle attacks and intercept authentication credentials.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.