Medium severity5.3NVD Advisory· Published Sep 13, 2023· Updated Jun 17, 2026
CVE-2023-27998
CVE-2023-27998
Description
A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.
Affected products
7cpe:2.3:a:fortinet:fortipresence:1.0.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:fortinet:fortipresence:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortipresence:1.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortipresence:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortipresence:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortipresence:1.2.1:*:*:*:*:*:*:*
- (no CPE)range: <=1.2.1, >=1.0.0
- (no CPE)range: 1.2.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-22-288nvdVendor Advisory
News mentions
0No linked articles in our index yet.