VYPR
Medium severity5.5NVD Advisory· Published Jun 4, 2020· Updated Jun 17, 2026

CVE-2019-16150

CVE-2019-16150

Description

Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensitive data via knowledge of the hard-coded key.

Affected products

3
  • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*+ 1 more
    • cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*range: <6.4.0
    • (no CPE)range: <6.4.0
  • Fortinet/FortiClientdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.