SB2025041032 - Observable Response Discrepancy in FortiClientEMS and FortiSOAR
Published: April 10, 2025 Updated: May 20, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Observable Response Discrepancy (CVE-ID: CVE-2024-36510)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to observable response discrepancy in authentication component. An unauthenticated attacker can enumerate valid users via observing login request responses.
Remediation
Install update from vendor's website.