FortiOS Configuration Backup Vulnerability in Fortinet Products
CVE-2019-6693
Key Information:
Badges
Summary
The vulnerability in FortiOS arises from the use of a hard-coded cryptographic key, which compromises the security of sensitive information stored in configuration backup files. Attackers with access to these backup files can decrypt crucial data, including user passwords (excluding the administrator's) and the passphrases for private keys and High Availability setups where applicable. This flaw poses significant risks for organizations relying on FortiOS for their operations.
Affected Version(s)
FortiGate 5.6.9 and below
FortiGate 6.0.5 and below
FortiGate 6.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved