CVE-2024-36510
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versio
Description
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
Weakness: CWE-204
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
| Fortinet | FortiSOAR | SIEM & Log Management | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiClientEMS
- Fortinet · FortiSOAR
Credit
Fortinet is pleased to thank Martin Stoynov from AMATAS for reporting this vulnerability under responsible disclosure and Hritik Sateesh from Fortinet Burnaby InfoSec team.
Vendor remediation
Please upgrade to FortiClientEMS version 7.4.1 or above Please upgrade to FortiClientEMS version 7.2.5 or above Please upgrade to FortiSOAR version 7.6.0 or above Please upgrade to FortiSOAR version 7.5.1 or above Please upgrade to FortiSOAR version 7.4.5 or above Please upgrade to FortiSOAR version 7.3.3 or above