Fortinet Fortipresence vulnerabilities
3 known vulnerabilities affecting fortinet/fortipresence.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-27998MEDIUMCVSS 5.3v1.0.0v1.1.0+5 more2023-09-13
CVE-2023-27998 [MEDIUM] CWE-756 CVE-2023-27998: A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 a
A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.
cvelistv5nvd
CVE-2022-41331CRITICALCVSS 9.8≥ 1.2.0, ≤ 1.2.1≥ 1.1.0, ≤ 1.1.1+1 more2023-04-11
CVE-2022-41331 [CRITICAL] CWE-306 CVE-2022-41331: A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructu
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.
cvelistv5nvd
CVE-2020-6641MEDIUMCVSS 4.3fixed in 20.12021-06-02
CVE-2020-6641 [MEDIUM] CWE-639 CVE-2020-6641: Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2
Two authorization bypass through user-controlled key vulnerabilities in the Fortinet FortiPresence 2.1.0 administration interface may allow an attacker to gain access to some user data via portal manager or portal users parameters.
nvd