Fortinet FortiOS < 5.6.10 / 6.0 < 6.0.7 / 6.2.x < 6.2.1 Vulnerable Encryption (FG-IR-19-007)

Medium Nessus Plugin ID 132317

Synopsis

The remote host is running a version of FortiOS that has not yet enabled private data encryption.

Description

The remote host is running a version of FortiOS that has not yet enabled private-data-encryption. A authorized remote user with access or knowledge of the standard encryption key could gain access and decrypt the FortiOS backup files and all non-administor passwords and private keys.' (CVE-2019-6693)

Solution

Ensure that Fortinet FortiOS has been updated to 5.6.10, 6.0.7, 6.2.1, or later.
Additionally the user will need to set the private-data-encryption attribute based on instructions contained in FG-IR-19-007 advisory.

See Also

https://fortiguard.com/psirt/FG-IR-19-007

Plugin Details

Severity: Medium

ID: 132317

File Name: fortios_FG-IR-19-007.nasl

Version: 1.8

Type: local

Family: Firewalls

Published: 2019/12/19

Updated: 2020/06/08

Dependencies: 12634, 73522

Risk Information

Risk Factor: Medium

CVSS Score Source: CVE-2019-6693

CVSS v2.0

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSS v3.0

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:fortinet:fortios

Required KB Items: Host/Fortigate/model, Host/Fortigate/version

Exploit Ease: No known exploits are available

Patch Publication Date: 2019/11/08

Vulnerability Publication Date: 2019/11/08

Reference Information

CVE: CVE-2019-6693