PT-2025-2455 · Fortinet · Forticlientems+1

Published

2025-01-14

·

Updated

2025-01-14

·

CVE-2024-36510

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: FortiClientEMS versions 7.0 through 7.4.0 FortiClientEMS version 7.2.0 through 7.2.4 FortiSOAR versions 6.4 through 7.5.0 FortiSOAR version 7.2.0 through 7.3.2 FortiSOAR version 7.4.0 through 7.4.4
Description: An observable response discrepancy issue may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
Recommendations: For FortiClientEMS versions 7.0 through 7.4.0, update to a version that includes a fix for this issue. For FortiClientEMS version 7.2.0 through 7.2.4, update to a version that includes a fix for this issue. For FortiSOAR versions 6.4 through 7.5.0, update to a version that includes a fix for this issue. For FortiSOAR version 7.2.0 through 7.3.2, update to a version that includes a fix for this issue. For FortiSOAR version 7.4.0 through 7.4.4, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to login functionality until a patch is available.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

BDU:2025-08810
CVE-2024-36510

Affected Products

Forticlientems
Fortisoar