Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hcp3-9rg5-2f9p

Опубликовано: 10 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.

An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.

EPSS

Процентиль: 3%
0.00015
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-1390

Связанные уязвимости

CVSS3: 4.8
nvd
8 месяцев назад

An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.

CVSS3: 4.8
fstec
8 месяцев назад

Уязвимость сервера управления программами Fortinet FortiClient Enterprise Management Server (EMS), связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить несанкционированный доступ на изменение, добавление или удаление данных

EPSS

Процентиль: 3%
0.00015
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-1390