Observable Response Discrepancy Vulnerability in Fortinet Products
CVE-2024-36510
4.9MEDIUM
Summary
An observable response discrepancy vulnerability exists in FortiClientEMS and FortiSOAR, allowing unauthenticated attackers to potentially enumerate valid users by analyzing the variations in login request responses. This could lead to an increased risk of unauthorized access and exploitation. It is crucial for organizations using these Fortinet products to implement remedial measures to safeguard user authentication mechanisms and ensure robust security practices.
Affected Version(s)
FortiClientEMS 7.2.0 <= 7.2.4
FortiClientEMS 7.0.0 <= 7.0.13
FortiSOAR 7.5.0
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published