{"api_version":"1","generated_at":"2026-07-23T08:55:31+00:00","cve":"CVE-2019-5587","urls":{"html":"https://cve.report/CVE-2019-5587","api":"https://cve.report/api/cve/CVE-2019-5587.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-5587","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-5587"},"summary":{"title":"CVE-2019-5587","description":"Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.","state":"PUBLIC","assigner":"psirt@fortinet.com","published_at":"2019-06-04 22:29:00","updated_at":"2022-04-22 20:11:00"},"problem_types":["CWE-345"],"metrics":[],"references":[{"url":"https://fortiguard.com/advisory/FG-IR-19-017","name":"https://fortiguard.com/advisory/FG-IR-19-017","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"VM images lack an integrity check of the file system at boot time | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/108628","name":"108628","refsource":"BID","tags":[],"title":"Fortinet FortiOS VM CVE-2019-5587 Local Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-5587","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5587","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"5587","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"5587","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-5587","ASSIGNER":"psirt@fortinet.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Fortinet","product":{"product_data":[{"product_name":"Fortinet FortiOS","version":{"version_data":[{"version_value":"FortiOS all versions below 6.0.5"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Execute unauthorized code or commands"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://fortiguard.com/advisory/FG-IR-19-017","url":"https://fortiguard.com/advisory/FG-IR-19-017"},{"refsource":"BID","name":"108628","url":"http://www.securityfocus.com/bid/108628"}]},"description":{"description_data":[{"lang":"eng","value":"Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods."}]}},"nvd":{"publishedDate":"2019-06-04 22:29:00","lastModifiedDate":"2022-04-22 20:11:00","problem_types":["CWE-345"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","versionEndExcluding":"6.0.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"5587","Ordinal":"143207","Title":"CVE-2019-5587","CVE":"CVE-2019-5587","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"5587","Ordinal":"1","NoteData":"Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"5587","Ordinal":"2","NoteData":"2019-06-04","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"5587","Ordinal":"3","NoteData":"2019-06-06","Type":"Other","Title":"Modified"}]}}}