Executive brief
FortiOS is the operating system used by Fortinet security devices to manage network traffic and security policies. A vulnerability exists where sensitive information in configuration backup files is protected by a universal, hard-coded password. If an attacker gains access to a backup file, they can easily decrypt it to steal user passwords, private security keys, and high-availability settings, potentially leading to full network compromise.
Technical details
A use of hard-coded credentials (CWE-798) exists in Fortinet FortiOS. The system uses a static cryptographic key to encrypt sensitive data within configuration backup files. An attacker who obtains a backup file can use knowledge of this hard-coded key to decrypt sensitive information, including non-administrator user passwords, private key passphrases, and High Availability (HA) passwords. While the CVSS score is 6.5 (Medium), the vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. Affected versions include 5.6.10 and below, 6.0.0 through 6.0.6, and 6.2.0.
Affected products
- Fortinet FortiOS <= 5.6.10, 6.0.0 to 6.0.6, 6.2.0
Timeline
- 2019-11-21: disclosed: Initial NVD publication
- 2025-06-25: kev added: Added to CISA Known Exploited Vulnerabilities catalog