VulnerabilityModified
CVE-2019-5587
Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.
MEDIUM 6.5EPSS 0.48%
Does this matter?
Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.
Description
Lack of root file system integrity checking in Fortinet FortiOS VM application images all versions below 6.0.5 may allow attacker to implant malicious programs into the installing image by reassembling the image through specific methods.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-345
- Affected
- fortinet/fortios
- Source
- psirt@fortinet.com
References
- http://www.securityfocus.com/bid/108628Broken Link
- https://fortiguard.com/advisory/FG-IR-19-017Vendor Advisory
- http://www.securityfocus.com/bid/108628Broken Link
- https://fortiguard.com/advisory/FG-IR-19-017Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.