An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://fortiguard.fortinet.com/psirt/FG-IR-23-375 |
![]() ![]() |
History
Wed, 16 Jul 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fortinet
Fortinet forticlientems |
|
CPEs | cpe:2.3:a:fortinet:forticlientems:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Fortinet
Fortinet forticlientems |
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Jun 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests. | |
Weaknesses | CWE-1390 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: fortinet
Published: 2025-06-10T16:36:15.059Z
Updated: 2025-06-10T19:39:57.140Z
Reserved: 2024-04-11T12:09:46.571Z
Link: CVE-2024-32119

Updated: 2025-06-10T19:29:59.031Z

Status : Analyzed
Published: 2025-06-10T17:19:14.323
Modified: 2025-07-16T15:20:12.983
Link: CVE-2024-32119

No data.