CVE-2019-5587

MEDIUM

Fortinet FortiOS < 6.0.5 - Unauthenticated Malicious Image Implantation via Root File System Integrity Bypass

Title source: llm
STIX 2.1

Description

Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-19-017
Broken Link vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108628

Scores

CVSS v3 6.5
EPSS 0.0010
EPSS Percentile 27.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-345
Status published
Products (1)
fortinet/fortios < 6.0.5
Published Jun 04, 2019
Tracked Since Feb 18, 2026