Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-32119


An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.


Published

2025-06-10T17:19:14.323

Last Modified

2025-07-16T15:20:12.983

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-1390

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application fortinet forticlientems ≤ 6.2.9 Yes
Application fortinet forticlientems ≤ 6.4.9 Yes
Application fortinet forticlientems ≤ 7.0.13 Yes
Application fortinet forticlientems < 7.2.5 Yes
Application fortinet forticlientems 7.4.0 Yes

References