VYPR

Forticlientems

by Fortinet

CVEs (28)

  • CVE-2025-22859MedMay 13, 2025
    risk 0.34cvss 5.3epss 0.01

    A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.

  • CVE-2024-32119MedJun 10, 2025
    risk 0.31cvss 4.8epss 0.00

    An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted…

  • CVE-2023-48786MedJun 10, 2025
    risk 0.28cvss 4.3epss 0.00

    A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.

  • CVE-2021-44172MedSep 13, 2023
    risk 0.28cvss 4.3epss 0.01

    An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information on environment…

  • CVE-2020-15940MedNov 2, 2021
    risk 0.27cvss 4.1epss 0.01

    An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter of various sections of the server.

  • CVE-2024-36506LowJan 14, 2025
    risk 0.24cvss 3.7epss 0.01

    An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection.

  • CVE-2025-22855LowApr 8, 2025
    risk 0.18cvss 2.7epss 0.00

    An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.

  • CVE-2026-59836HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via

Page 2 of 2