TROYANOSYVIRUS
Volver a CVEs

CVE-2019-6693

MEDIUMCISA KEV
6.5

Descripcion

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

Detalles CVE

Puntuacion CVSS v3.16.5
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado11/21/2019
Ultima modificacion10/24/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorFortinet
ProductoFortiOS
Nombre vulnerabilidadFortinet FortiOS Use of Hard-Coded Credentials Vulnerability
Fecha inclusion KEV2025-06-25
Fecha limite remediacion2025-07-16
Uso en ransomwareKnown

Productos afectados

fortinet:fortios

Debilidades (CWE)

CWE-798CWE-798

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.