CVE-2019-6698
published 2019-08-23CVE-2019-6698: Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.52%
71.6th percentile
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder device.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticameras | — | — |
| fortinet | fortirecorder | — | — |
| fortinet | fortirecorder100d | — | — |
| fortinet | fortirecorder200d | — | — |
| fortinet | fortirecorder400d | — | — |
| fortinet | fortirecorder_firmware | < 2.7.4 | 2.7.4 |
| fortinet | fortirecorderfirmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target unauthenticated access attempts to FortiCameras managed by FortiRecorder devices, particularly those leveraging hard-coded credentials (CWE-798) ↗
- →Monitor for unauthenticated login attempts to FortiCamera management interfaces, especially from unexpected source IPs, which may indicate exploitation of hard-coded credentials ↗
- ·All FortiRecorder versions below 2.7.4 are affected; upgrade to 2.7.4 or above to remediate the hard-coded credentials issue across all affected hardware models (FortiRecorder100d, FortiRecorder200d, FortiRecorder400d) ↗
- ·FortiCameras are only exploitable via this vulnerability if they are actively managed by a vulnerable FortiRecorder device; standalone cameras not managed by FortiRecorder are not directly at risk via this vector ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7f85-jgjr-85qj: Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2
ghsa_unreviewed·2022-05-24
CVE-2019-6698 [CRITICAL] CWE-798 GHSA-7f85-jgjr-85qj: Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder device.
Fortinet
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attac...
vendor_fortinet·2019-08-23·CVSS 9.8
CVE-2019-6698 [CRITICAL] CWE-798 Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attac...
FG-IR-19-185: Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attac...
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder device.
CVEs: CVE-2019-6698
CWEs: CWE-798
CVSS: 9.8 (critical)
Affected products: FortiCameras, FortiRecorder, FortiRecorder100d, FortiRecorder200d, FortiRecorder400d, FortiRecorderfirmware
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-23
Published