Vulnerability Description
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Forticlientems | >= 7.0.0, < 7.2.5 |
| Fortinet | Fortisoar | >= 6.4.0, < 7.3.3 |
Related Weaknesses (CWE)
References
- https://fortiguard.fortinet.com/psirt/FG-IR-24-071Vendor Advisory
FAQ
What is CVE-2024-36510?
CVE-2024-36510 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versio...
How severe is CVE-2024-36510?
CVE-2024-36510 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-36510?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Forticlientems, Fortinet Fortisoar.