CVE-2024-23106: Fortinet FortiClient EMS

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.

Affected products

  • Fortinet FortiClient EMS: from 6.2.0, up to and including 6.2.9; from 6.4.0, up to and including 6.4.9; from 7.0.0, before 7.0.11 (fixed in 7.0.11); from 7.2.0, before 7.2.5 (fixed in 7.2.5)

Published 2025-01-14. Last modified 2026-06-17.