5.3
CVE-2023-27998
- EPSS 0.22%
- Published 13.09.2023 13:15:08
- Last modified 21.11.2024 07:53:54
- Source psirt@fortinet.com
- Teams watchlist Login
- Open Login
A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.
Data is provided by the National Vulnerability Database (NVD)
Fortinet ≫ Fortipresence Version1.0.0
Fortinet ≫ Fortipresence Version1.1.0
Fortinet ≫ Fortipresence Version1.1.1
Fortinet ≫ Fortipresence Version1.2.0
Fortinet ≫ Fortipresence Version1.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.22% | 0.446 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
psirt@fortinet.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-755 Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
CWE-756 Missing Custom Error Page
The product does not return custom error pages to the user, possibly exposing sensitive information.