CVE-2024-23106

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 307

Summary

CVE-2024-23106 is a vulnerability affecting FortiClientEMS versions 7.2.0 through 7.2.4 and older than 7.0.10. This issue involves an insufficient restriction of authentication attempts, classified as CWE-307. An attacker, who remains unauthenticated, can execute brute force attacks against the FortiClientEMS console through crafted HTTP or HTTPS requests. This vulnerability poses a significant risk, allowing unauthorized access to sensitive information, potentially leading to system compromise. It is crucial for organizations using FortiClientEMS to update their software promptly to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Fortinet FortiClient

Affected Vendors

  • Fortinet