CVE-2019-6693General(fortinet / fortios)

LOWCVSS 6.5 · MEDIUMCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-07-16. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • General: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
fortios

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-17: 1Mentions · 2026-05-25: 1Mentions · 2026-07-27: 104-1705-2507-27
Signal classification1 categories
General
3100.0%
Referenced assets1 URL
Full discourse3 posts
  • rgacz@rgacz
    General

    Je to skoro 1,5 roku od Belsen Group leak, který zneužíval zranitelnosti CVE-2022-40684 (2022-10-18) a CVE-2019-6693 (2019-11-21). Po skoro 4 letech od této zranitelnosti stále běží tisíce zařízení na zranitelném FortiOS 7.0.0 až 7.0.6 a 7.2.0 a 7.2.1.

    Post summary

    The post highlights that Belsen Group exploited CVE‑2022‑40684 and CVE‑2019‑6693 and notes that many FortiOS devices have remained vulnerable for years, but it provides no additional technical details, PoC, exploit code or remediation information.

    1000052
    539 followersView on X
  • Dave@RideToFireStar
    General

    @jamieantisocial First thing that popped into my head was one of my favorite FortiFails™️: CVE-2019-6693 😆

    Post summary

    The tweet merely references CVE-2019-6693 without providing any additional context or indicators.

    0001072
    1.2K followersView on X
  • tumit@tumit
    General

    Decrypting FortiGate passwords (CVE-2019–6693) by Bart Dopheide https://medium.com/p/decrypting-fortigate-passwords-cve-2019-6693-1239f6fd5a61?source=social.tw

    Post summary

    The article title references FortiGate password decryption for CVE-2019‑6693, but the provided text offers no substantive details about exploitation techniques, mitigations, or confirmation of active attacks.

    0000046
    315 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
OSfortinetfortios6.2.0--

Explore more