Unpassworded remotely accessible Redis & MongoDB
Summary
A missing authentication for critical function vulnerability [CWE-306] in FortiPresence on-prem infrastructure server may allow a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.
Note: The amount of deployed on-prem instances is minimal. The Cloud instances of FortiPresence are not impacted.
| Version | Affected | Solution |
|---|---|---|
| FortiPresence 20 | Not affected | Not Applicable |
| FortiPresence 2.0 | Not affected | Not Applicable |
| FortiPresence 1.2 | 1.2 all versions | Migrate to a fixed release |
| FortiPresence 1.1 | 1.1 all versions | Migrate to a fixed release |
| FortiPresence 1.0 | 1.0 all versions | Migrate to a fixed release |
Acknowledgement
Fortinet is pleased to thank the customer who reported this vulnerability under responsible disclosure.
Timeline
2023-03-28: Initial publication