Telemetry protocol authentication is based over VDOM and FCTUID

Summary

An improper authentication vulnerability [CWE-287] in FortiClientEMS telemetry protocol may allow an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.

Version Affected Solution
FortiClientEMS 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiClientEMS 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiClientEMS 7.0 7.0 all versions Migrate to a fixed release
FortiClientEMS 6.4 6.4 all versions Migrate to a fixed release
FortiClientEMS 6.2 6.2 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2025-06-10: Initial publication