EMS console login under brute force attack does not get locked

Summary

An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS may allow an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.

Version Affected Solution
FortiClientEMS 7.4 Not affected Not Applicable
FortiClientEMS 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.5 or above
FortiClientEMS 7.0 7.0.0 through 7.0.10 Upgrade to 7.0.11 or above
FortiClientEMS 6.4 6.4 all versions Migrate to a fixed release
FortiClientEMS 6.2 6.2 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Adib Rahimi of Fortinet QA team.

Timeline

2025-01-14: Initial publication