FG-IR-19-037: FG default configuration is not secure/ By default, FG does not verify LDAP server identity
Published Jul 26, 2019
·Updated
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
Affected Software
1 affected component
Fortinet FortiGate
Event History
Aug 20, 2026
Advisory Published
via FortiGuard·12:07 PM
Data Sourced
via FortiGuard·12:07 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which deployments are exposed to this issue?
FortiGate deployments that use LDAP and do not verify the LDAP server's identity are exposed. The attacker must be on the same subnet as the affected device.
2
What does an attacker need to exploit the vulnerability?
No authentication or user interaction is required. An attacker on the same subnet can impersonate the LDAP server to intercept sensitive information.
3
Are default settings affected?
Yes. The issue is caused by the default configuration not verifying LDAP server identity.