cbcvebase.
CVE-2019-6698
published 2019-08-23

CVE-2019-6698: Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.52%
71.6th percentile
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder device.

Affected

7 ranges
VendorProductVersion rangeFixed in
fortinetforticameras
fortinetfortirecorder
fortinetfortirecorder100d
fortinetfortirecorder200d
fortinetfortirecorder400d
fortinetfortirecorder_firmware< 2.7.42.7.4
fortinetfortirecorderfirmware

Detection & IOCsextracted from sources · hover to see the quote

  • Target unauthenticated access attempts to FortiCameras managed by FortiRecorder devices, particularly those leveraging hard-coded credentials (CWE-798)
  • Monitor for unauthenticated login attempts to FortiCamera management interfaces, especially from unexpected source IPs, which may indicate exploitation of hard-coded credentials
  • ·All FortiRecorder versions below 2.7.4 are affected; upgrade to 2.7.4 or above to remediate the hard-coded credentials issue across all affected hardware models (FortiRecorder100d, FortiRecorder200d, FortiRecorder400d)
  • ·FortiCameras are only exploitable via this vulnerability if they are actively managed by a vulnerable FortiRecorder device; standalone cameras not managed by FortiRecorder are not directly at risk via this vector

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.