BOOK THIS SPACE FOR AD
ARTICLE ADFortinet addressed a critical vulnerability that can lead to remote, unauthenticated access to Redis and MongoDB instances.
Fortinet has addressed a critical vulnerability, tracked as CVE-2022-41331 (CVSS score of 9.3), in its Fortinet FortiPresence data analytics solution.
FortiPresence is a comprehensive data analytics solution designed for analyzing user traffic and deriving usage patterns.
Successful exploitation can lead to remote, unauthenticated access to Redis and MongoDB instances via crafted authentication requests.
“A missing authentication for critical function vulnerability [CWE-306] in FortiPresence on-prem infrastructure server may allow a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.” reads the advisory published by the vendor.
The vulnerability affects FortiPresence 1.2 all versions, FortiPresence 1.1 all versions, and FortiPresence 1.0 all versions. The company added that Cloud instances of FortiPresence are not impacted.
Fortinet addressed multiple vulnerabilities in its products as part of its “April 2023 Vulnerability Advisories,” below are the most severe ones:
CVE-2022-43955 (CVSS score of 8) – FortiWeb – XSS vulnerability in HTML generated attack report files CVE-2022-27487 (CVSS score of 8.3) FortiSandbox / FortiDeceptor – Improper profile-based access control over APIs CVE-2022-41330 (CVSS score of 8.3) FortiOS & FortiProxy – Cross Site Scripting vulnerabilities in administrative interfaceCustomers are recommended to update their instances as soon as possible.
Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections:
Please nominate Security Affairs as your favorite blog.
Nominate here: https://docs.google.com/forms/d/e/1FAIpQLSfaFMkrMlrLhOBsRPKdv56Y4HgC88Bcji4V7OCxCm_OmyPoLw/viewform
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Fortinet)