CVE-2019-5587
Last modified
CVE-2019-5587 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | < 6.0.5 |
References
- http://www.securityfocus.com/bid/108628Broken Link
- https://fortiguard.com/advisory/FG-IR-19-017Vendor Advisory
- http://www.securityfocus.com/bid/108628Broken Link
- https://fortiguard.com/advisory/FG-IR-19-017Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5587?
How severe is CVE-2019-5587?
How do I fix CVE-2019-5587?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5581Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5582Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5583Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5584Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-5585An improper access control vulnerability in FortiClientMac b…
- CVE-2019-5586A reflected Cross-Site-Scripting (XSS) vulnerability in Fort…
- CVE-2019-5588A reflected Cross-Site-Scripting (XSS) vulnerability in Fort…
- CVE-2019-5589An Unsafe Search Path vulnerability in FortiClient Online In…
- CVE-2019-5590The URL part of the report message is not encoded in Fortine…
- CVE-2019-5591A Default Configuration vulnerability in FortiOS may allow a…6.5
- CVE-2019-5592Multiple padding oracle vulnerabilities (Zombie POODLE, GOLD…5.9
- CVE-2019-5593Improper permission or value checking in the CLI console may…5.5
Are you affected by CVE-2019-5587?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
