← Back to browse · API

CVE-2019-6693

Severity
MEDIUM
CVSS
6.5
EPSS
0.05663
Risk score
52.98
CISA KEV
Yes
PoC
No
Published
2019-11-21
Modified
2026-08-04
First seen
2026-08-05
Aliases
EUVD-2019-16251, GHSA-HX92-84X6-67MX
Products
Fortinet:FortiGate 5.6.9 and below, Fortinet:FortiGate 6.0.5 and below, Fortinet:FortiGate 6.2.0, Fortinet:FortiOS, fortinet:fortios
Sources
nvd CVE-2019-6693
cisa.gov CVE-2019-6693
euvd EUVD-2019-16251

Description

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

References