CVE-2019-6693 KEV
6.5
MEDIUM · CVSS 3.1 · EPSS 5.8% (pctl 93)
Patch first
On CISA KEV — known exploited in the wild, due 2025-07-16.
Description
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).
Scoring
| CVSS | 6.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 5.83% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | yes — remediate by 2025-07-16 |
| Public exploit | none known |
| Published | 2019-11-21 |
| Last modified | 2026-08-04 |
CISA KEV
| Name | Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability |
|---|---|
| Added | 2025-06-25 |
| Due | 2025-07-16 |
| Vendor / product | Fortinet / FortiOS |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| fortinet | fortios |
References
→ the Explorer · watch your stack · NVD