Observable Response Discrepancy Vulnerability in Fortinet Products
CVE-2024-36510

4.9MEDIUM

Key Information:

Vendor
Fortinet
Vendor
CVE Published:
14 January 2025

Summary

An observable response discrepancy vulnerability exists in FortiClientEMS and FortiSOAR, allowing unauthenticated attackers to potentially enumerate valid users by analyzing the variations in login request responses. This could lead to an increased risk of unauthorized access and exploitation. It is crucial for organizations using these Fortinet products to implement remedial measures to safeguard user authentication mechanisms and ensure robust security practices.

Affected Version(s)

FortiClientEMS 7.2.0 <= 7.2.4

FortiClientEMS 7.0.0 <= 7.0.13

FortiSOAR 7.5.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.