CVE-2024-23106
published 2025-01-14CVE-2024-23106: An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.92%
56.3th percentile
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlientems | — | — |
| fortinet | forticlientems | 6.2.0 – 6.2.9 | — |
| fortinet | forticlientems | 6.2.6 – 6.2.9 | — |
| fortinet | forticlientems | 6.4.0 – 6.4.9 | — |
| fortinet | forticlientems | 6.4.7 – 6.4.9 | — |
| fortinet | forticlientems | >= 7.0.0 < 7.0.11 | 7.0.11 |
| fortinet | forticlientems | 7.0.0 – 7.0.10 | — |
| fortinet | forticlientems | >= 7.2.0 < 7.2.5 | 7.2.5 |
| fortinet | forticlientems | 7.2.0 – 7.2.3 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect brute force authentication attempts against FortiClientEMS console via HTTP or HTTPS — monitor for excessive failed login requests from a single source IP targeting the EMS login endpoint ↗
- →Alert on high volumes of unauthenticated HTTP/HTTPS authentication requests to FortiClientEMS (versions 7.2.0–7.2.4 or before 7.0.10) — no account lockout or rate-limiting is enforced, making rapid sequential login attempts a reliable signal ↗
- ·Affected versions are FortiClientEMS 7.2.0 through 7.2.4 and all versions before 7.0.10 — detections and mitigations should be scoped to these version ranges ↗
- ·The vulnerability is exploitable by unauthenticated attackers, meaning no prior credential or session is required — network-level access to the EMS console (HTTP/HTTPS) is the only prerequisite ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cf8f-f7r9-xpmh: An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7
ghsa_unreviewed·2025-01-14
CVE-2024-23106 [HIGH] CWE-307 GHSA-cf8f-f7r9-xpmh: An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.
Fortinet
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and...
vendor_fortinet·2025-01-14·CVSS 8.1
CVE-2024-23106 [HIGH] CWE-307 An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and...
FG-IR-23-476: An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and...
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.
CVEs: CVE-2024-23106
CWEs: CWE-307
CVSS: 8.1 (high)
Affected products: FortiClientEMS, FortiClientems
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-14
Published