CVE-2024-36510
published 2025-01-14CVE-2024-36510: An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.70%
48.9th percentile
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlientems | — | — |
| fortinet | forticlientems | — | — |
| fortinet | forticlientems | >= 7.0.0 < 7.2.5 | 7.2.5 |
| fortinet | forticlientems | 7.0.0 – 7.0.13 | — |
| fortinet | forticlientems | 7.2.0 – 7.2.4 | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | — | — |
| fortinet | fortisoar | >= 6.4.0 < 7.3.3 | 7.3.3 |
| fortinet | fortisoar | 6.4.0 – 6.4.1 | — |
| fortinet | fortisoar | 6.4.3 – 6.4.4 | — |
| fortinet | fortisoar | 7.0.0 – 7.0.3 | — |
| fortinet | fortisoar | 7.2.0 – 7.2.2 | — |
| fortinet | fortisoar | 7.3.0 – 7.3.2 | — |
| fortinet | fortisoar | >= 7.4.0 < 7.4.5 | 7.4.5 |
| fortinet | fortisoar | 7.4.0 – 7.4.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version...
vendor_fortinet·2025-01-14·CVSS 5.3
CVE-2024-36510 [MEDIUM] CWE-203 An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version...
FG-IR-24-071: An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version...
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
CVEs: CVE-2024-36510
CWEs: CWE-203, CWE-204
CVSS: 5.3 (medium)
Affected products: FortiClientEMS, FortiClientems, FortiSOAR
GHSA
GHSA-g58r-fcx4-mv8r: An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7
ghsa_unreviewed·2025-01-14
CVE-2024-36510 [MEDIUM] CWE-203 GHSA-g58r-fcx4-mv8r: An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-14
Published