cbcvebase.
CVE-2024-23106
published 2025-01-14

CVE-2024-23106: An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.92%
56.3th percentile
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetforticlientems
fortinetforticlientems6.2.0 – 6.2.9
fortinetforticlientems6.2.6 – 6.2.9
fortinetforticlientems6.4.0 – 6.4.9
fortinetforticlientems6.4.7 – 6.4.9
fortinetforticlientems>= 7.0.0 < 7.0.117.0.11
fortinetforticlientems7.0.0 – 7.0.10
fortinetforticlientems>= 7.2.0 < 7.2.57.2.5
fortinetforticlientems7.2.0 – 7.2.3

Detection & IOCsextracted from sources · hover to see the quote

  • Detect brute force authentication attempts against FortiClientEMS console via HTTP or HTTPS — monitor for excessive failed login requests from a single source IP targeting the EMS login endpoint
  • Alert on high volumes of unauthenticated HTTP/HTTPS authentication requests to FortiClientEMS (versions 7.2.0–7.2.4 or before 7.0.10) — no account lockout or rate-limiting is enforced, making rapid sequential login attempts a reliable signal
  • ·Affected versions are FortiClientEMS 7.2.0 through 7.2.4 and all versions before 7.0.10 — detections and mitigations should be scoped to these version ranges
  • ·The vulnerability is exploitable by unauthenticated attackers, meaning no prior credential or session is required — network-level access to the EMS console (HTTP/HTTPS) is the only prerequisite
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.