CVE-2019-5591
ENISA EUVD: EUVD-2019-15166 ↗
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 20, 2026
4 articles
EPSS Score
Source: FIRST.org · 2026-05-24
50.55%
probability
This CVE has a 50.55% probability
of being exploited in the next 30 days.
0%
Top 97.9th percentile of all CVEs
100%
CVSS v3.1
Source: NVD6.5
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
Attack Intelligence
Exploits & PoC
ayewo/fortios-ldap-mitm-poc-CVE-2019-5591
The default configuration of LDAP on FortiOS v6.0.x to v6.2.0 does not check server identity for LDAP/S leading to MITM attacks. This PoC demos full e
1
1 repo — triés par ⭐
Rechercher sur GitHub ↗
Fortinet delays patching zero-day allowing remote server takeover
BleepingComputer
Aug 17, 2021
CISA Alert: Top Routinely Exploited Vulnerabilities
Qualys
Jul 29, 2021
Signal Intelligence
Confidence
75%
EPSS
50.55%
CVSS v3.1
6.5
Mentions
4
Last Seen
Aug 17, 2021
CNA Information
Analyst Note
BleepingComputer article explicitly labels CVE-2019-5591 as a 'zero-day allowing remote server takeover' with Fortinet delays in patching. TheHackerNews confirms an unpatched OS command injection in FortiWeb. The 2019 CVE year combined with contemporary reporting of active exploitation and delayed patches supports zero-day classification.
Threat Actors 4
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
APT42
apt_group
Information theft and espionage
🇮🇷 IR
Triage Info
Decided atMar 20, 2026