FortiPresence - Unpassworded remotely accessible Redis & MongoDB

Summary

A missing authentication for critical function vulnerability [CWE-306] in FortiPresence on-prem infrastructure server may allow a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.

Note: The amount of deployed on-prem instances is minimal. The Cloud instances of FortiPresence are not impacted.

Affected Products

FortiPresence 1.2 all versions
FortiPresence 1.1 all versions
FortiPresence 1.0 all versions

Solutions

Please upgrade to FortiPresence version 2.0.0 or above

Acknowledgement

Fortinet is pleased to thank the customer who reported this vulnerability under responsible disclosure.

Timeline

2023-03-28: Initial publication