Security readout for executives and security teams
Plain-English summary
This issue means certain Fortinet SSL VPN products may store logged-in user credentials in cleartext session files. If someone can read those files on the device, they may recover VPN credentials. The impact is credential exposure, not direct system takeover in the supplied CVE data.
Executive priority
Treat this as a moderate credential-protection issue. It should be prioritized for internet-facing VPN environments and environments where device backups or admin access are widely shared, but the supplied evidence does not support emergency treatment based on active exploitation.
Technical view
CVE-2019-17655 is a CWE-313 cleartext storage flaw affecting FortiOS SSL VPN and FortiProxy versions listed in the CVE. An attacker who can read the targeted device's session file may retrieve a logged-in SSL VPN user's credentials. CVSS 3.1 is 5.3 with confidentiality impact only.
Likely exposure
Exposure is limited to Fortinet FortiOS SSL VPN 6.2.0-6.2.2, 6.0.9 and earlier, and FortiProxy 2.0.0, 1.2.9 and earlier. Risk is higher where administrative, filesystem, backup, or diagnostic access to appliance files is broadly available.
Exploitation context
The source bundle does not show CISA KEV listing or any cited evidence of active exploitation. The stated prerequisite is the ability to read the session file on the targeted device, so this is most relevant after local, administrative, backup, or appliance-file access is obtained.
Researcher notes
The key condition is file-read access to session data on the targeted Fortinet device. The public bundle does not provide exploit details, fixed version numbers, or observed exploitation evidence, so validation should focus on affected versions, SSL VPN use, and access paths to appliance files.
Mitigation direction
- Identify affected FortiOS SSL VPN and FortiProxy deployments.
- Check Fortinet PSIRT advisories for fixed versions and upgrade guidance.
- Restrict administrative, filesystem, backup, and diagnostic access to appliance files.
- Review access logs for unusual appliance file access or credential handling.
- Rotate credentials for users whose session files may have been exposed.
Validation and detection
- Inventory FortiOS and FortiProxy versions against the affected ranges.
- Confirm whether SSL VPN is enabled on affected FortiOS systems.
- Review who can access appliance session files, backups, or diagnostics.
- Check whether vendor remediation from Fortinet PSIRT has been applied.
- Assess whether exposed VPN credentials require reset or session revocation.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-17655 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.3 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N3.91.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.3MediumVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://fortiguard.com/psirt/FG-IR-19-217CVE reference · x_refsource_CONFIRM
- https://fortiguard.com/psirt/FG-IR-20-224CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
