CVE-2024-23106: Critical severity fortinet ems vulnerability
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23106?
CVE-2024-23106 is categorized as a high severity vulnerability due to the potential for unauthorized access through brute force attacks.
How do I fix CVE-2024-23106?
To mitigate CVE-2024-23106, upgrade FortiClientEMS to version 7.2.5 or later, or to version 7.0.10 or later.
What versions of FortiClientEMS are affected by CVE-2024-23106?
CVE-2024-23106 affects FortiClientEMS versions 7.2.0 through 7.2.4 and any version before 7.0.10.
What type of attack does CVE-2024-23106 allow?
CVE-2024-23106 allows an unauthenticated attacker to perform brute force attacks against the FortiClientEMS console.
Is authentication required to exploit CVE-2024-23106?
No, CVE-2024-23106 can be exploited without authentication, making it particularly dangerous.