CVE-2019-6693
Act now ● On CISA KEV — actively exploited used in ransomware
Actively exploited — on the CISA KEV list.
CVSS base
6.5
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS — probability of exploitation (30 days)
5.8%
92.8th percentile
CISA KEV
Listed
Added 2025-06-25 · patch by 2025-07-16
Weakness / dates
CWE-798
Published 2019-11-21 · modified 2026-08-04
CVSS breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Privileges Required | L | Low |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | H | High |
| Integrity | N | None |
| Availability | N | None |
Timeline
- 2019-11-21 — Published (NVD)
- 2025-06-25 — Added to CISA KEV (actively exploited)
- 2025-07-16 — CISA patch-by deadline
- 2026-08-04 — Last modified (NVD)
Description
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).