An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.
References
Link | Resource |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-375 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Jul 2025, 15:20
Type | Values Removed | Values Added |
---|---|---|
First Time |
Fortinet
Fortinet forticlientems |
|
References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-375 - Vendor Advisory | |
CPE | cpe:2.3:a:fortinet:forticlientems:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:* |
12 Jun 2025, 16:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Jun 2025, 17:19
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-10 17:19
Updated : 2025-07-16 15:20
NVD link : CVE-2024-32119
Mitre link : CVE-2024-32119
CVE.ORG link : CVE-2024-32119
JSON object : View
Products Affected
fortinet
- forticlientems
CWE