CVE-2023-27998CWE-756

A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated…

Medium · published September 13, 2023

CVSS v3.1
5.3
EPSS
0%
Percentile
33.3
In the wild
Unconfirmed
What it is

A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ability to navigate to the login GUI to gain sensitive information via navigating to specific HTTP(s) paths.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:X/RC:C
CVSS v4.0
Not supplied
EPSS
0.00400 · 33.3th percentile
Weakness
CWE-756 · Missing Custom Error Page
Published
2023-09-13T12:29Z
EPSS history
Timeline
  • 13 SEP 12:29Z
    A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated…
    cvelistv5