Vulnerability record · CVE-2019-6693 · published 21 November 2019
CVE-2019-6693: FortiOS hard-coded key exposes backup file secrets
Fortinet · Fortios
FortiOS configuration backup files are encrypted with a hard-coded cryptographic key, so anyone who obtains a backup can decrypt the sensitive data it contains. The exposed data includes user passwords (excluding the administrator password), private key passphrases, and the High Availability password when configured. Because the key is static and embedded in the product, the confidentiality of every affected backup depends on keeping the file out of an attacker's hands.
Description
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is in CISA KEV with known ransomware use and exposes reusable credentials, though exploitation requires prior access to a backup file.
What it is
FortiOS configuration backup files are encrypted with a hard-coded cryptographic key, so anyone who obtains a backup can decrypt the sensitive data it contains. The exposed data includes user passwords (excluding the administrator password), private key passphrases, and the High Availability password when configured. Because the key is static and embedded in the product, the confidentiality of every affected backup depends on keeping the file out of an attacker's hands.
Impact
An attacker who obtains a backup file recovers user passwords, private key passphrases, and the HA password, enabling credential reuse, lateral movement, and access to key material. The administrator password is not exposed by this flaw.
Attack surface
The vector is network-reachable with low privileges required and no user interaction (AV:N/AC:L/PR:L/UI:N). The attacker must first gain access to a configuration backup file, so the flaw is reached through possession of that file rather than by direct exploitation of a listening service.
Exploitation
CVE-2019-6693 is listed in CISA KEV with a due date of 2025-07-16 and is flagged for known ransomware campaign use. EPSS gives a 30-day probability of 0.05663 (92.6th percentile), and the vendor advisory is tagged Mitigation and Vendor Advisory.
What to do
- Apply the Fortinet fix per advisory FG-IR-19-007 and upgrade FortiOS to a corrected release.
- Restrict access to configuration backup files and store them encrypted at rest with access limited to authorized administrators.
- Rotate user passwords, private key passphrases, and the HA password contained in any backup that may have been exposed.
- Follow CISA BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable.
- Audit where backups are stored, transmitted, and shared, and remove stale copies.
Detection
- Monitor for access, copying, or exfiltration of FortiOS configuration backup files.
- Alert on authentication attempts or logins using credentials that appeared in a backup, especially for non-administrator accounts.
- Review logs for unexpected High Availability configuration changes or HA password use.
- Track FortiOS versions in the environment against the fixed release from FG-IR-19-007.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-6693 to the Known Exploited Vulnerabilities catalog on 25 June 2025 as "Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 July 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/advisory/FG-IR-19-007 | MitigationVendor Advisory |
| https://fortiguard.com/advisory/FG-IR-19-007 | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-6693 | US Government Resource |
Track CVE-2019-6693 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-6693), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.