First published: Wed Sep 13 2023(Updated: )
A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.
Credit: psirt@fortinet.com psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiPresence | =1.0.0 | |
Fortinet FortiPresence | =1.1.0 | |
Fortinet FortiPresence | =1.1.1 | |
Fortinet FortiPresence | =1.2.0 | |
Fortinet FortiPresence | =1.2.1 |
Please upgrade to FortiPresence version 2.0.0 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-27998.
The severity level of CVE-2023-27998 is medium with a CVSS score of 5.3.
FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 are affected by CVE-2023-27998.
CVE-2023-27998 allows an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.
To fix CVE-2023-27998, it is recommended to update FortiPresence to a version that is not affected by the vulnerability.