CVE-2024-36510: Medium severity fortinet ems vulnerability
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36510?
CVE-2024-36510 has been rated as a moderate severity vulnerability due to its potential for user enumeration by unauthenticated attackers.
How do I fix CVE-2024-36510?
To fix CVE-2024-36510, Fortinet recommends upgrading to the latest versions of FortiClientEMS and FortiSOAR that are not affected by this vulnerability.
Which versions of FortiClientEMS are affected by CVE-2024-36510?
FortiClientEMS versions 7.4.0, 7.2.0 through 7.2.4, and all versions of 7.0 are affected by CVE-2024-36510.
Which versions of FortiSOAR are affected by CVE-2024-36510?
FortiSOAR versions 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, and all versions of 7.2, 7.0, and 6.4 are affected by CVE-2024-36510.
What type of attack does CVE-2024-36510 enable?
CVE-2024-36510 enables an unauthenticated attacker to enumerate valid usernames, posing a risk for further targeted attacks.