Fortinet fixed a critical vulnerability in its Data Analytics product
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-27487 | A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0. A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perform unauthorized API calls via crafted HTTP or HTTPS requests. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2022-41331 +1 in the same advisory: …41330 | A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthentica A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2022-43955 | An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all version An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow an unauthenticated and remote attacker to perform a reflected cross site scripting attack (XSS) via injecting malicious payload in log entries used to build report. NVD description · AI analysis pending | 6.1 | <1% |
| — |
Full article295 words · extracted from securityaffairs.com · click to collapse

Fortinet addressed a critical vulnerability that can lead to remote, unauthenticated access to Redis and MongoDB instances.
Fortinet has addressed a critical vulnerability, tracked as CVE-2022-41331 (CVSS score of 9.3), in its Fortinet FortiPresence data analytics solution.
FortiPresence is a comprehensive data analytics solution designed for analyzing user traffic and deriving usage patterns.
Successful exploitation can lead to remote, unauthenticated access to Redis and MongoDB instances via crafted authentication requests.
“A missing authentication for critical function vulnerability [CWE-306] in FortiPresence on-prem infrastructure server may allow a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.” reads the advisory published by the vendor.
The vulnerability affects FortiPresence 1.2 all versions, FortiPresence 1.1 all versions, and FortiPresence 1.0 all versions. The company added that Cloud instances of FortiPresence are not impacted.
Fortinet addressed multiple vulnerabilities in its products as part of its “April 2023 Vulnerability Advisories,” below are the most severe ones:
- CVE-2022-43955 (CVSS score of 8) – FortiWeb – XSS vulnerability in HTML generated attack report files
- CVE-2022-27487 (CVSS score of 8.3) FortiSandbox / FortiDeceptor – Improper profile-based access control over APIs
- CVE-2022-41330 (CVSS score of 8.3) FortiOS & FortiProxy – Cross Site Scripting vulnerabilities in administrative interface
Customers are recommended to update their instances as soon as possible.
Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections:
- The Teacher – Most Educational Blog
- The Entertainer – Most Entertaining Blog
- The Tech Whizz – Best Technical Blog
- Best Social Media Account to Follow (@securityaffairs)
Please nominate Security Affairs as your favorite blog.
Nominate here: https://docs.google.com/forms/d/e/1FAIpQLSfaFMkrMlrLhOBsRPKdv56Y4HgC88Bcji4V7OCxCm_OmyPoLw/viewform
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Fortinet)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/144750/security/fortinet-critical-vulnerability-data-analytics.html