A missing authentication for critical function...
Critical severity
Unreviewed
Published
Apr 11, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Apr 11, 2023
Published to the GitHub Advisory Database
Apr 11, 2023
Last updated
Apr 4, 2024
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.
References