ZeroHour

CVE-2019-6693

KEV ransomwaremass

Hard-Coded Encryption Key in Fortinet FortiOS Configuration Backups

CISA: Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

CVSS 3.1
6.5 medium
EPSS
6%p93
Published
()
KEV added
AI analysis

FortiOS encrypts sensitive data inside configuration backup files using a hard-coded cryptographic key, meaning anyone who knows that fixed key can decrypt the data. An attacker who obtains a FortiOS configuration backup file - whether stored locally, transferred over the network, or held in a central backup repository - can decipher the protected contents offline without touching the firewall itself. The exposed data includes non-administrator user passwords, private key passphrases, and the High Availability password (when set), giving attackers credentials that can be reused for further access; CISA notes known ransomware use. Organizations running affected Fortinet FortiOS releases that create, store, or transfer configuration backups are affected. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-06-25 with ransomware exploitation reported, and EPSS puts the 30-day exploitation probability at 5.6% (92nd percentile); no public PoC is known.

What to do: Inventory FortiOS deployments and locate all configuration backup files, including copies moved off-box to TFTP servers or central backup repositories, and restrict who can read them. Rotate exposed non-administrator user passwords, private-key passphrases, and High Availability passwords, since the hard-coded key means any accessible backup should be treated as plaintext. Upgrade FortiOS to a fixed release per Fortinet's security advisory, apply mitigations per vendor instructions or BOD 22-01 guidance for cloud services, and check logs for evidence that backup files were accessed or exfiltrated.

Affected
Fortinet FortiOS
Estimated exposure
massmillions of FortiGate/FortiOS installations worldwide, with hundreds of thousands of FortiOS devices visible in public internet scans — Fortinet's FortiGate installed base is reported in the millions and public Shodan/Censys-style scans consistently show several hundred thousand internet-exposed FortiOS management/VPN interfaces, though practical impact here is limited to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

CISA Known Exploited Vulnerability
Affected
Fortinet FortiOS
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
fortinet
Products
fortios
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news