QID 43825
Date Published: 2021-04-05
QID 43825: Fortigate FortiOS Default Configuration(FG-IR-19-037)
FortiOS is a security-hardened, purpose-built operating system that is the software foundation of FortiGate.
It is affected with following vulnerability:
CVE-2019-5591 : A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet
to intercept sensitive information by impersonating the LDAP server.
Affected Products :
FortiOS 6.2.0 and below. Enabling the CLI option that checks for LDAP server identity entirely prevents the issue. Potential detection as cannot determine server-identity-check enabled or disabled.
Note: FortiOS 6.2.1 and above have server-identity-check enabled by default, when installed from scratch.
Upgrading from 6.0.3 - 6.2.0 to 6.2.1 and above does not suffice to thwart the
issue: server-identity-check must be enabled (prior the upgrade of after, indifferently) to solve this.
QID Detection Logic (Authenticated) :
Detection checks for vulnerable version of FortiOS.
On Successful exploitation could lead to information disclosure.
A workaround exists, enabling the CLI option that checks for LDAP server identity entirely prevents the issue. This option can be enabled only if secure and ca-cert of the LDAP server are set. Following commands can be used for this cli option: config user ldap edit ldap-server set ca-cert set secure ldaps set server-identity-check enable
- FG-IR-19-037 -
www.fortiguard.com/psirt/FG-IR-19-037
CVEs related to QID 43825
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-19-037 | FortiOS |
|