CRITICAL
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests
Published Apr 11, 2023
9.8
CRITICALCVSS 3.1
EPSS 1.27%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.