CVE-2019-5592 describes multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementation of FortiOS IPS engine versions 5.000 to 5.006, 4.000 to 4.036, 4.200 to 4.219, and 3.547 and below. This flaw allows an attacker to decipher TLS connections passing through a FortiGate device when SSL Deep Inspection and the IPS sensor are enabled, by monitoring traffic in a Man-in-the-Middle position. The vulnerability has a CVSS score of 5.9 (Medium), indicating a network attack vector with high attack complexity and high confidentiality impact, but no integrity or availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting low current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.00547CPE matchmatch criteria | cpe:2.3:a:fortinet:fortios_ips_engine:*:*:*:*:*:*:*:* | ||
>= 4.00000, <= 4.00036CPE matchmatch criteria | cpe:2.3:a:fortinet:fortios_ips_engine:*:*:*:*:*:*:*:* | ||
>= 4.00200, <= 4.00219CPE matchmatch criteria | cpe:2.3:a:fortinet:fortios_ips_engine:*:*:*:*:*:*:*:* | ||
>= 5.00000, <= 5.00006CPE matchmatch criteria | cpe:2.3:a:fortinet:fortios_ips_engine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.