CVE-2024-23106
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack ag
Severity
High 7.7
CVSS 3.1
Exploited
Not listed
EPSS
0.009
57.6th percentile
Discovered by
Not disclosed
Published
Jan 14, 2025
Assigned by fortinet
Description
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.
Weakness: CWE-307
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiClient | Endpoint / EDR | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiClientEMS
Vendor remediation
Please upgrade to FortiClientEMS version 7.4.0 or above Please upgrade to FortiClientEMS version 7.2.5 or above Please upgrade to FortiClientEMS version 7.0.11 or above