5.3
CVE-2023-27998
- EPSS 0.22%
- Veröffentlicht 13.09.2023 13:15:08
- Zuletzt bearbeitet 21.11.2024 07:53:54
- Quelle psirt@fortinet.com
- Teams Watchlist Login
- Unerledigt Login
A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortipresence Version1.0.0
Fortinet ≫ Fortipresence Version1.1.0
Fortinet ≫ Fortipresence Version1.1.1
Fortinet ≫ Fortipresence Version1.2.0
Fortinet ≫ Fortipresence Version1.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.22% | 0.446 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
psirt@fortinet.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-755 Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
CWE-756 Missing Custom Error Page
The product does not return custom error pages to the user, possibly exposing sensitive information.