VYPR
Medium severity5.3NVD Advisory· Published Sep 13, 2023· Updated Jun 17, 2026

CVE-2023-27998

CVE-2023-27998

Description

A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.

Affected products

7
  • cpe:2.3:a:fortinet:fortipresence:1.0.0:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:fortinet:fortipresence:1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortipresence:1.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortipresence:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortipresence:1.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortipresence:1.2.1:*:*:*:*:*:*:*
    • (no CPE)range: <=1.2.1, >=1.0.0
    • (no CPE)range: 1.2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.