Medium severity5.5NVD Advisory· Published Jun 4, 2020· Updated Jun 17, 2026
CVE-2019-16150
CVE-2019-16150
Description
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensitive data via knowledge of the hard-coded key.
Affected products
3cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*+ 1 more
- cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*range: <6.4.0
- (no CPE)range: <6.4.0
- Fortinet/FortiClientdescription
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-19-194nvdVendor Advisory
News mentions
0No linked articles in our index yet.