User enumeration in authentication component

Summary

An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS and FortiSOAR may allow an unauthenticated attacker to enumerate valid users via observing login request responses.

Version Affected Solution
FortiClientEMS 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiClientEMS 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiClientEMS 7.0 7.0 all versions Migrate to a fixed release
FortiSOAR on-premise 7.6 Not affected Not Applicable
FortiSOAR on-premise 7.5 7.5.0 Upgrade to 7.5.1 or above
FortiSOAR on-premise 7.4 7.4.0 through 7.4.4 Upgrade to 7.4.5 or above
FortiSOAR on-premise 7.3 7.3.0 through 7.3.2 Upgrade to 7.3.3 or above
FortiSOAR on-premise 7.2 7.2 all versions Migrate to a fixed release
FortiSOAR on-premise 7.0 7.0 all versions Migrate to a fixed release
FortiSOAR on-premise 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Martin Stoynov from AMATAS for reporting this vulnerability under responsible disclosure and Hritik Sateesh from Fortinet Burnaby InfoSec team.

Timeline

2025-01-14: Initial publication