peter bassill · operator
$ cve CVE-2019-6693 JSON

CVE-2019-6693 KEV

6.5
MEDIUM · CVSS 3.1 · EPSS 5.8% (pctl 93)

Patch first

On CISA KEV — known exploited in the wild, due 2025-07-16.

Description

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS5.83% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-798
On CISA KEVyes — remediate by 2025-07-16
Public exploitnone known
Published2019-11-21
Last modified2026-08-04

CISA KEV

NameFortinet FortiOS Use of Hard-Coded Credentials Vulnerability
Added2025-06-25
Due2025-07-16
Vendor / productFortinet / FortiOS
Ransomware useknown

Affected (1)

VendorProduct
fortinetfortios

References

→ the Explorer  ·  watch your stack  ·  NVD