An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-375 |
![]() ![]() |
History
Tue, 10 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Jun 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests. | |
Weaknesses | CWE-1390 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: fortinet
Published: 2025-06-10T16:36:15.059Z
Updated: 2025-06-10T19:39:57.140Z
Reserved: 2024-04-11T12:09:46.571Z
Link: CVE-2024-32119

Updated: 2025-06-10T19:29:59.031Z

Status : Awaiting Analysis
Published: 2025-06-10T17:19:14.323
Modified: 2025-06-12T16:06:39.330
Link: CVE-2024-32119

No data.