Improper verification of source of a communication channel in administrative interface

Summary

An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS may allow a remote attacker to bypass the trusted host feature via session connection.

Version Affected Solution
FortiClientEMS Cloud 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiClientEMS Cloud 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiClientEMS Cloud 7.0 7.0 all versions Migrate to a fixed release
FortiClientEMS Cloud 6.4 6.4 all versions Migrate to a fixed release
FortiClientEMS 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiClientEMS 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above
FortiClientEMS 7.0 7.0 all versions Migrate to a fixed release
FortiClientEMS 6.4 6.4 all versions Migrate to a fixed release

Fortinet in Q2/24 has remediated this issue in FortiSASE version 24.2.c.

Acknowledgement

Fortinet is pleased to thank Bryan Edwards for reporting this vulnerability under responsible disclosure.

Timeline

2025-01-14: Initial publication