CVE-2019-6693
Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
Description
CVE-2019-6693 is a medium-severity vulnerability in Fortinet FortiOS involving the use of a hard-coded cryptographic key to encrypt sensitive data in configuration backup files. An authenticated attacker with low privileges who gains access to a FortiOS configuration backup can decrypt all sensitive data within it — including VPN credentials, LDAP bind passwords, and administrative secrets — using the publicly known static key. Rated CVSS v3.1 6.5, this weakness fundamentally undermines the confidentiality of FortiGate firewall configuration backups. CISA added CVE-2019-6693 to the Known Exploited Vulnerabilities catalog with a deadline of July 16, 2025, and its EPSS score of 72.22% at the 99th percentile indicates near-certain exploitation. This vulnerability is associated with known ransomware campaigns targeting Fortinet infrastructure.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| fortinet | fortios | <= 5.6.10; >= 6.0.0, <= 6.0.6; 6.2.0 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
References
- https://fortiguard.com/advisory/FG-IR-19-007(Mitigation, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-6693(US Government Resource)
Weakness Type
CWE-798: Use of Hard-coded Credentials
CVE-2019-6693 is classified under CWE-798, Use of Hard-coded Credentials. The FortiOS firmware contains a static, hard-coded cryptographic key that is used to encrypt sensitive data within configuration backup files. Because the key is embedded in the firmware and is the same across all FortiGate devices, any party who extracts or discovers the key can decrypt sensitive fields in any FortiOS configuration backup, regardless of the device it came from.
Learn more: CWE-798 — Use of Hard-coded Credentials
Impact Analysis
CVE-2019-6693 has severe confidentiality implications for organizations using FortiGate firewalls. The attack is network-accessible (AV:N) with low complexity (AC:L), requiring only low-level authentication (PR:L) and no user interaction (UI:N). Confidentiality impact is high (C:H) because the hard-coded encryption key allows complete decryption of all sensitive data in FortiOS configuration backups, including VPN pre-shared keys, LDAP and RADIUS authentication credentials, SSL certificate private keys, administrative passwords, and SNMP community strings. An attacker who obtains a configuration backup — whether through another vulnerability, misconfigured backup storage, insider access, or social engineering — can immediately decrypt all embedded secrets. The EPSS score of 72.22% at the 99th percentile confirms widespread exploitation, and the association with known ransomware campaigns demonstrates that threat actors actively target FortiGate configuration data to extract VPN credentials for initial access to enterprise networks.
Exploit Maturity
CVE-2019-6693 has reached high exploit maturity, with CISA confirming active exploitation and association with known ransomware campaigns. The hard-coded encryption key has been publicly documented, and tools for decrypting FortiOS configuration backups are readily available to attackers. The FortiGuard advisory (FG-IR-19-007) acknowledges the vulnerability and provides mitigation guidance. The EPSS score of 72.22% at the 99th percentile places this among the most exploited Fortinet vulnerabilities. Ransomware groups have been documented using FortiGate VPN credentials extracted from decrypted configuration backups to gain initial access to target networks, making this vulnerability a critical component of the attack chain. The long-standing nature of the issue (disclosed in 2019) combined with the large installed base of FortiGate appliances ensures a persistent target surface for credential-harvesting campaigns.
Remediation
-
Upgrade FortiOS to a version that uses per-device encryption keys for configuration backup files. Update beyond FortiOS 5.6.10, 6.0.6, and 6.2.0 to the latest available release for your hardware platform. Refer to the FortiGuard advisory FG-IR-19-007 for specific version guidance.
-
Set a strong encryption password for configuration backups by using the FortiOS CLI command to configure a custom backup encryption password. This password overrides the hard-coded key and provides device-specific encryption:
config system global / set private-data-encryption enable / end. -
Secure all existing configuration backup files that were created with vulnerable FortiOS versions. Treat any configuration backup created without a custom encryption password as compromised — rotate all credentials contained within, including VPN pre-shared keys, LDAP bind passwords, RADIUS secrets, and administrative credentials.
-
Restrict access to FortiOS configuration backups by implementing strict file-level permissions on backup storage locations, encrypting backup repositories with separate keys, and limiting the number of administrators who can generate or access backup files.
-
Implement monitoring for credential abuse by watching for unauthorized VPN connections using credentials that may have been extracted from configuration backups. Enable multi-factor authentication on all FortiGate VPN and administrative access to reduce the impact of compromised static credentials.
Technical Details
CVE-2019-6693 is a hard-coded cryptographic key vulnerability in Fortinet FortiOS, with the CVSS v3.1 vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N indicating that an authenticated attacker with low privileges can extract highly sensitive data over the network. When FortiOS generates a configuration backup file, it encrypts sensitive fields (passwords, keys, secrets) using a symmetric encryption algorithm with a key that is hard-coded in the firmware. This key is identical across all FortiGate devices running the affected FortiOS versions, meaning that knowledge of the key — which can be extracted by reverse-engineering the firmware — enables decryption of sensitive data in any FortiOS configuration backup. The affected versions include FortiOS 5.6.x through 5.6.10, FortiOS 6.0.x through 6.0.6, and FortiOS 6.2.0. The vulnerability is particularly dangerous because configuration backups are routinely stored on network file shares, backup servers, and cloud storage, often with less stringent access controls than the firewalls themselves. An attacker who obtains a backup through any means gains access to the complete credential set of the firewall deployment.
Frequently Asked Questions
Is CVE-2019-6693 being actively exploited?
Yes. CISA has confirmed active exploitation and associates CVE-2019-6693 with known ransomware campaigns. The EPSS score of 72.22% at the 99th percentile confirms widespread exploitation. Threat actors use extracted VPN credentials from FortiGate backups as an initial access vector for network compromise.
What products are affected by CVE-2019-6693?
Fortinet FortiOS versions 5.6.x through 5.6.10, 6.0.x through 6.0.6, and 6.2.0 are affected. All FortiGate firewall appliances running these versions use the same hard-coded encryption key for configuration backup files.
How do I fix CVE-2019-6693?
Upgrade FortiOS to a patched version and enable private data encryption with a custom password using set private-data-encryption enable. Additionally, rotate all credentials stored in configuration backups created with vulnerable versions.
How severe is CVE-2019-6693?
With a CVSS score of 6.5 (Medium) but an EPSS score of 72.22% at the 99th percentile, the practical severity is very high. The vulnerability exposes all sensitive credentials in FortiGate configuration backups, enabling VPN credential theft that ransomware groups actively exploit for initial network access.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.