LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-6693: Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 25, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 16, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-6693 to its Known Exploited Vulnerabilities catalog on Jun 25, 2025, with a federal patch deadline of Jul 16, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.

CVE-2019-6693 is a hard-coded credentials weakness in Fortinet FortiOS. An attacker who knows the fixed key can decrypt sensitive material inside a FortiOS configuration backup file. Because configuration backups often hold credentials, certificates, and network topology, successful abuse can give an adversary a detailed map of the environment and material useful for further access. The vulnerability has been linked to ransomware activity, so organizations running FortiOS should treat it as a priority for inventory and remediation.

Public detail is limited to the CISA description; exact affected builds, CVSS scores, and exploit mechanics must be confirmed against the vendor advisory.

How it works

The flaw belongs to CWE-798 (Use of Hard-Coded Credentials). FortiOS embeds a fixed cryptographic key that is used when the system encrypts (or “ciphers”) portions of its configuration backup. Anyone who obtains a backup file and already knows that key can reverse the encryption and recover the protected data. No remote code execution is implied by the published summary; the attack surface is possession of a configuration backup together with knowledge of the hard-coded key. Once the sensitive content is readable, an attacker can harvest credentials or other secrets for lateral movement or ransomware deployment.

Am I affected? How to find it in your systems

FortiOS is the operating system that runs on Fortinet FortiGate firewalls and related appliances, both on-premises and in some cloud or virtual form factors. Inventory every FortiGate device, virtual machine, and managed FortiOS instance in your estate. Record the exact FortiOS version string shown in the GUI or via the CLI command that displays system status. Compare those versions against the fixed releases listed in the Fortinet advisory for CVE-2019-6693; do not rely on generic version ranges.

If the version is listed as vulnerable or if you cannot determine the version, treat the device as affected until the vendor advisory confirms otherwise.

How to remediate

Apply the vendor-supplied FortiOS update that addresses CVE-2019-6693. Follow the upgrade path and release notes published by Fortinet; test the new build in a non-production environment first if your change-control process requires it. After the patch is installed, generate a fresh configuration backup and verify that the new encryption behavior is in use. Rotate any credentials, certificates, or shared secrets that may have been present in earlier backups. Document the remediation and retain evidence of the version change for audit purposes. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the fixed FortiOS release can be deployed, reduce exposure with compensating controls:

These steps do not eliminate the hard-coded key but shrink the window in which an attacker can obtain and decrypt a backup.

If your data may have been exposed

Actively exploited vulnerabilities, including those used by ransomware operators, frequently lead to broader breaches. If configuration backups left your control or if you observe indicators of compromise, assume that any secrets inside those files are compromised and rotate them. Review logs for follow-on activity and engage your incident-response process. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether related credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiOS
WeaknessCWE-798
Added to CISA KEVJun 25, 2025
Federal patch deadlineJul 16, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities