CVE-2019-6693

Description

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users passwords (except the administrators password), private keys passphrases and High Availability password (when set).

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
72.223

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-13367 ,CVE-2019-5591 ,CVE-2019-5593 ,CVE-2019-6693 are affected in fortios 6.2.0NCM
Use of Hard-coded Credentials Vulnerability (CVE-2019-6693)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234