CVE-2019-6693
KEV ransomwaremassHard-Coded Encryption Key in Fortinet FortiOS Configuration Backups
CISA: Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
FortiOS encrypts sensitive data inside configuration backup files using a hard-coded cryptographic key, meaning anyone who knows that fixed key can decrypt the data. An attacker who obtains a FortiOS configuration backup file - whether stored locally, transferred over the network, or held in a central backup repository - can decipher the protected contents offline without touching the firewall itself. The exposed data includes non-administrator user passwords, private key passphrases, and the High Availability password (when set), giving attackers credentials that can be reused for further access; CISA notes known ransomware use. Organizations running affected Fortinet FortiOS releases that create, store, or transfer configuration backups are affected. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-06-25 with ransomware exploitation reported, and EPSS puts the 30-day exploitation probability at 5.6% (92nd percentile); no public PoC is known.
What to do: Inventory FortiOS deployments and locate all configuration backup files, including copies moved off-box to TFTP servers or central backup repositories, and restrict who can read them. Rotate exposed non-administrator user passwords, private-key passphrases, and High Availability passwords, since the hard-coded key means any accessible backup should be treated as plaintext. Upgrade FortiOS to a fixed release per Fortinet's security advisory, apply mitigations per vendor instructions or BOD 22-01 guidance for cloud services, and check logs for evidence that backup files were accessed or exfiltrated.
| Fortinet FortiOS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).
- Affected
- Fortinet FortiOS
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- fortinet
- Products
- fortios
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N