An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-23-375 |     | 
History
                    Wed, 16 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Fortinet Fortinet forticlientems | |
| CPEs | cpe:2.3:a:fortinet:forticlientems:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:forticlientems:7.4.0:*:*:*:*:*:*:* | |
| Vendors & Products | Fortinet Fortinet forticlientems | 
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Tue, 10 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 10 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests. | |
| Weaknesses | CWE-1390 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: fortinet
Published: 2025-06-10T16:36:15.059Z
Updated: 2025-06-10T19:39:57.140Z
Reserved: 2024-04-11T12:09:46.571Z
Link: CVE-2024-32119
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-06-10T19:29:59.031Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-06-10T17:19:14.323
Modified: 2025-07-16T15:20:12.983
Link: CVE-2024-32119
 Redhat
                        Redhat
                    No data.