LiveActive security incident?Get immediate response
CVE Record

CVE-2019-17655: A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6....

A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.

MediumCVSS 5.3Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This issue means certain Fortinet SSL VPN products may store logged-in user credentials in cleartext session files. If someone can read those files on the device, they may recover VPN credentials. The impact is credential exposure, not direct system takeover in the supplied CVE data.

Executive priority

Treat this as a moderate credential-protection issue. It should be prioritized for internet-facing VPN environments and environments where device backups or admin access are widely shared, but the supplied evidence does not support emergency treatment based on active exploitation.

Technical view

CVE-2019-17655 is a CWE-313 cleartext storage flaw affecting FortiOS SSL VPN and FortiProxy versions listed in the CVE. An attacker who can read the targeted device's session file may retrieve a logged-in SSL VPN user's credentials. CVSS 3.1 is 5.3 with confidentiality impact only.

Likely exposure

Exposure is limited to Fortinet FortiOS SSL VPN 6.2.0-6.2.2, 6.0.9 and earlier, and FortiProxy 2.0.0, 1.2.9 and earlier. Risk is higher where administrative, filesystem, backup, or diagnostic access to appliance files is broadly available.

Exploitation context

The source bundle does not show CISA KEV listing or any cited evidence of active exploitation. The stated prerequisite is the ability to read the session file on the targeted device, so this is most relevant after local, administrative, backup, or appliance-file access is obtained.

Researcher notes

The key condition is file-read access to session data on the targeted Fortinet device. The public bundle does not provide exploit details, fixed version numbers, or observed exploitation evidence, so validation should focus on affected versions, SSL VPN use, and access paths to appliance files.

Mitigation direction

  • Identify affected FortiOS SSL VPN and FortiProxy deployments.
  • Check Fortinet PSIRT advisories for fixed versions and upgrade guidance.
  • Restrict administrative, filesystem, backup, and diagnostic access to appliance files.
  • Review access logs for unusual appliance file access or credential handling.
  • Rotate credentials for users whose session files may have been exposed.

Validation and detection

  • Inventory FortiOS and FortiProxy versions against the affected ranges.
  • Confirm whether SSL VPN is enabled on affected FortiOS systems.
  • Review who can access appliance session files, backups, or diagnostics.
  • Check whether vendor remediation from Fortinet PSIRT has been applied.
  • Assess whether exposed VPN credentials require reset or session revocation.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-17655 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.3 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.3CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N3.91.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

5.3Medium
CVSS 3.1 vector shape for CVE-2019-17655Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
FortinetFortinet FortiOS and FortiProxyFortiOS 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlierListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.