CVE-2019-6693
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).
- Affected products
- Fortianalyzer, Fortimanager, Fortios
- Fortinet Fortios
- ≤ 5.6.10, 6.0.6, 6.2.0
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 5.6% (92th percentile)
- Weakness
- CWE-798
- NVD status
- Analyzed
- Published
- 2019-11-21
CVE-2019-6693 at NVD
5 known exploits for CVE-2019-6693
Proof-of-concept code and exploit modules indexed by Sploitus