A missing authentication for critical function vulnerability [CWE-306] in FortiPresence on-prem infrastructure server may allow a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.
Note: The amount of deployed on-prem instances is minimal.Â The Cloud instances of FortiPresence are not impacted.
FortiPresence 1.2 all versions
FortiPresence 1.1 all versions
FortiPresence 1.0 all versions
SolutionsPlease upgrade to FortiPresence version 2.0.0 or above
AcknowledgementFortinet is pleased to thank the customer who reported this vulnerability under responsible disclosure.
2023-03-28: Initial publication