EMS console login under brute force attack does not get locked
Summary
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS may allow an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.
| Version | Affected | Solution |
|---|---|---|
| FortiClientEMS 7.4 | Not affected | Not Applicable |
| FortiClientEMS 7.2 | 7.2.0 through 7.2.3 | Upgrade to 7.2.5 or above |
| FortiClientEMS 7.0 | 7.0.0 through 7.0.10 | Upgrade to 7.0.11 or above |
| FortiClientEMS 6.4 | 6.4 all versions | Migrate to a fixed release |
| FortiClientEMS 6.2 | 6.2 all versions | Migrate to a fixed release |