CVE-2022-41331: Critical severity fortinet fortiproxy ssl vpn webmode vulnerability
Published Apr 11, 2023
·Updated
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.
Affected Software
1 affected component
Fortinet FortiProxy>=1.0.0<2.0.0
Remediation
Information
Please upgrade to FortiPresence version 2.0.0 or above
Event History
Apr 11, 2023
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-41331.
2
What is the severity level of CVE-2022-41331?
The severity level of CVE-2022-41331 is critical (9.8).
3
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-306.
4
How does this vulnerability affect FortiPresence infrastructure server?
This vulnerability allows a remote, unauthenticated attacker to access the Redis and MongoDB instances of FortiPresence infrastructure server before version 1.2.1 via crafted authentication requests.
5
How can I fix this vulnerability?
To fix this vulnerability, update FortiPresence infrastructure server to version 1.2.1 or later.