An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection.
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Forticlientems | Fortinet | 6.4.0 (including) | 7.2.5 (excluding) |
Forticlientems | Fortinet | 7.4.0 (including) | 7.4.0 (including) |
Forticlientems_cloud | Fortinet | 6.4.0 (including) | 7.2.5 (excluding) |
Forticlientems_cloud | Fortinet | 7.4.0 (including) | 7.4.0 (including) |