First published: Tue Apr 11 2023(Updated: )
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiProxy | >=1.0.0<2.0.0 |
Please upgrade to FortiPresence version 2.0.0 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-41331.
The severity level of CVE-2022-41331 is critical (9.8).
The CWE ID for this vulnerability is CWE-306.
This vulnerability allows a remote, unauthenticated attacker to access the Redis and MongoDB instances of FortiPresence infrastructure server before version 1.2.1 via crafted authentication requests.
To fix this vulnerability, update FortiPresence infrastructure server to version 1.2.1 or later.