CVE-2019-6693
Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
- Published
- Nov 21, 2019
- Updated
- Aug 4, 2026
- Assigning CNA
- fortinet
- Evidence observed
- Jun 25, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NLow · next 30 days
- Percentile
- 92.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).
Sources
4- CVE-2019-6693Exploit
Decrypts FortiGate configuration secrets (CVE-2019-6693) for versions below 6.2.0, extracting encrypted passwords and keys from dumped configs using a unique or custom key.
- CVE-2019-6693Scanner
Decrypt FortiGate configuration files and encrypted strings to detect default encryption keys, enabling rapid assessment of CVE-2019-6693 vulnerability.
- cve-2019-6693Exploit
An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all non-administator passwords, private keys and High Availability passwords.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.