---
id: CVE-2019-6693
title: >-
  Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS
  configuration backup file may allow an attacker with access to the backup file
  to decipher the sensitive data, via knowledge of the hard-coded key
summary: >-
  Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS
  configuration backup file may allow an attacker with access to the backup file
  to decipher the sensitive data, via knowledge of the hard-coded key. The
  aforementio…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-798
  - CWE-798
vendor: fortinet
product: fortios
affected:
  - fortios <= 5.6.10
  - 'fortios >= 6.0.0, <= 6.0.6'
  - fortios = 6.2.0
published: '2019-11-21'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-6693'
references:
  - url: 'https://fortiguard.com/advisory/FG-IR-19-007'
    label: psirt@fortinet.com
  - url: 'https://fortiguard.com/advisory/FG-IR-19-007'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-6693
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.05828
epssPercentile: 0.92832
kev: true
kevDateAdded: '2025-06-25'
kevDueDate: '2025-07-16'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-04T05:36:12.127Z'
exploits:
  github: 4
  githubRepos:
    - 'https://github.com/gquere/CVE-2019-6693'
    - 'https://github.com/synacktiv/CVE-2020-9289'
    - 'https://github.com/saladandonionrings/cve-2019-6693'
  checkedAt: '2026-09-24T07:52:46.914Z'
exploitAvailable: true
---

## Overview

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

## Affected

- `fortios <= 5.6.10`
- `fortios >= 6.0.0, <= 6.0.6`
- `fortios = 6.2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
