Fortinet FortiClient EMS Improper Verification of Communication Source Vulnerability Allowing Trusted Host Bypass

Vulnerability

A vulnerability allowing for improper verification of the source of a communication channel has been identified in Fortinet FortiClient EMS versions 7.4.0, 7.2.0 through 7.2.4, 7.0 (all versions), and 6.4 (all versions). This vulnerability may enable a remote attacker to bypass the trusted host feature by manipulating session connections.

Impact

Exploitation of this vulnerability could lead to unauthorized bypassing of the trusted host feature, potentially allowing for unauthorized access or actions within the FortiClient EMS environment.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
0.6
exploitability
7.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.