<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>FortiRecorder sets hardcoded admin password on all FortiCameras</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-19-185</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2019-08-12T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2019-08-12T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2019-08-12T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            An Use of Hard-coded Credentials vulnerability in FortiRecorder may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder device.
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="2">
            Escalation of privilege
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="3">
            FortiRecorder all versions below 2.7.4
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="4">
            Upgrade to FortiRecorder 2.7.4Workarounds:Deploy FortiCameras on a private and closed network dedicated to the connection to FortiRecorder.Alternatively, use a Firewall or FortiCamera built-in access control to only allow trusted hosts to access FortiCamera.Refer to the &#34;Hardening security&#34; section in your FortiRecorder&#39;s admin guide for guidance.
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:DocumentReferences>
        <cvrf:Reference>
            <cvrf:URL>https://fortiguard.fortinet.com/psirt/FG-IR-19-185</cvrf:URL>
            <cvrf:Description>FortiRecorder sets hardcoded admin password on all FortiCameras</cvrf:Description>
        </cvrf:Reference>
        <cvrf:Reference>
            <cvrf:URL>https://xor.cat/2019/08/05/fortinet-fortirecorder-hardcoded-password/</cvrf:URL>
            <cvrf:Description>https://xor.cat/2019/08/05/fortinet-fortirecorder-hardcoded-password/</cvrf:Description>
        </cvrf:Reference>
    </cvrf:DocumentReferences>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Fortinet is pleased to thank security researcher Aaron Blair for reporting this vulnerability under responsible disclosure and FortiGuard Lion Team for the help of addressing this issue.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <Vulnerability Ordinal="1">
        <Title>FortiRecorder sets hardcoded admin password on all FortiCameras</Title>
        <cvrf:CVE>CVE-2019-6698</cvrf:CVE>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>7.1</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:F/RL:X/RC:X</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-19-185</URL>
                <Description>FortiRecorder sets hardcoded admin password on all FortiCameras</Description>
            </Reference>Reference>
            <Reference>
                <URL>https://xor.cat/2019/08/05/fortinet-fortirecorder-hardcoded-password/</URL>
                <Description>https://xor.cat/2019/08/05/fortinet-fortirecorder-hardcoded-password/</Description>
            </Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>