FortiPresence - Unpassworded remotely accessible Redis & MongoDB
Summary
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence on-prem infrastructure server may allow a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.
Â
Note: The amount of deployed on-prem instances is minimal. The Cloud instances of FortiPresence are not impacted.
Affected Products
FortiPresence 1.2 all versions
FortiPresence 1.1 all versions
FortiPresence 1.0 all versions
Solutions
Please upgrade to FortiPresence version 2.0.0 or aboveAcknowledgement
Fortinet is pleased to thank the customer who reported this vulnerability under responsible disclosure.Timeline
2023-03-28: Initial publication