Skip to content
COOEY

EXPOSURES › CVE-2019-6693

CVE-2019-6693

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-06-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-6693 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildhardcoded-credsdata-breachunpatched

Fortinet FortiOS shipped with hard-coded credentials allowing attackers to decrypt sensitive data from configuration backups.

Fortinet FortiOS contained hard-coded credentials that enabled attackers to decrypt sensitive data from configuration backup files. This is a severe compliance failure for DIB organizations because it violates the principle of least privilege and exposes sensitive data to decryption without proper authentication. Organizations must audit their Fortinet deployments for known hard-coded credentials and apply patches immediately to prevent data exposure and compliance violations.

Shame score — Hard-coded credentials in a core security product are a fundamental design flaw that is entirely avoidable and directly enables data decryption, representing a severe negligence failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.