CVE-2019-6693
KEV
🔴 Łataj teraz
Użycie twardo zakodowanego klucza kryptograficznego w FortiOS umożliwia odszyfrowanie wrażliwych danych.
CVSS
6.5
EPSS
5.7%
Exploit
weaponized
Vendor
fortinet
Opis źródłowy (NVD)
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 5.7% |
| Opublikowano (NVD) | 2019-11-21 16:15:13 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-04 05:16:27 UTC |
Referencje
- https://fortiguard.com/advisory/FG-IR-19-007 (psirt@fortinet.com) [Mitigation, Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-6693 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]