Unpassworded remotely accessible Redis & MongoDB

Summary

A missing authentication for critical function vulnerability [CWE-306] in FortiPresence on-prem infrastructure server may allow a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.

Note: The amount of deployed on-prem instances is minimal. The Cloud instances of FortiPresence are not impacted.

Version Affected Solution
FortiPresence 20 Not affected Not Applicable
FortiPresence 2.0 Not affected Not Applicable
FortiPresence 1.2 1.2 all versions Migrate to a fixed release
FortiPresence 1.1 1.1 all versions Migrate to a fixed release
FortiPresence 1.0 1.0 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank the customer who reported this vulnerability under responsible disclosure.

Timeline

2023-03-28: Initial publication