Description
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiPresence version 2.0.0 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-44538 | A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-22-355 |
|
History
Wed, 23 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-10-23T14:29:35.185Z
Reserved: 2022-09-23T15:07:35.782Z
Link: CVE-2022-41331
Updated: 2024-08-03T12:42:44.883Z
Status : Modified
Published: 2023-04-11T17:15:07.437
Modified: 2024-11-21T07:23:04.220
Link: CVE-2022-41331
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD