Vulnerability Description
Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder device.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortirecorder Firmware | < 2.7.4 |
| Fortinet | Fortirecorder 100D | - |
| Fortinet | Fortirecorder 200D | - |
| Fortinet | Fortirecorder 400D | - |
Related Weaknesses (CWE)
References
- https://fortiguard.com/advisory/FG-IR-19-185Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-19-185Vendor Advisory
FAQ
What is CVE-2019-6698?
CVE-2019-6698 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to Forti...
How severe is CVE-2019-6698?
CVE-2019-6698 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-6698?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortirecorder Firmware, Fortinet Fortirecorder 100D, Fortinet Fortirecorder 200D, Fortinet Fortirecorder 400D.