CVE-2019-6698

Severity
9.8CRITICAL
EPSS
0.8%
top 25.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateMay 24

Description

Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder device.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5fortinet_fortirecorderFortiRecorder all versions below 2.7.4

🔴Vulnerability Details

2
GHSA
GHSA-7f85-jgjr-85qj: Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 22022-05-24
CVEList
CVE-2019-6698: Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 22019-08-23

📋Vendor Advisories

1
Fortinet
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attac...2019-08-23
CVE-2019-6698 (CRITICAL CVSS 9.8) | Use of Hard-coded Credentials vulne | cvebase.io