CVE-2024-23106

CWE-3074 documents4 sources
Severity
9.8CRITICAL
EPSS
0.9%
top 24.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 14

Description

An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/forticlientems7.0.07.0.11+3
CVEListV5fortinet/forticlientems7.2.07.2.3+5

🔴Vulnerability Details

2
GHSA
GHSA-cf8f-f7r9-xpmh: An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 72025-01-14
CVEList
CVE-2024-23106: An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 72025-01-14

📋Vendor Advisories

1
Fortinet
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and...2025-01-14
CVE-2024-23106 (CRITICAL CVSS 9.8) | An improper restriction of excessiv | cvebase.io