SB2025041032 - Observable Response Discrepancy in FortiClientEMS and FortiSOAR
Published: April 10, 2025 Updated: May 20, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Observable Response Discrepancy (CVE-ID: CVE-2024-36510)
CWE-ID: CWE-204 - Observable Response Discrepancy
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to observable response discrepancy in authentication component. An unauthenticated attacker can enumerate valid users via observing login request responses.
Remediation
Install update from vendor's website.