Impact
The flaw is an improper certificate validation error (CWE‑295) in Fortinet FortiClientEMS. Because the client does not properly verify certificates, sensitive information can be exposed if an attacker can trick the client into trusting a malicious certificate. The CVE provides no explicit attack vector; it is inferred that the weakness could be exploited remotely by manipulating traffic that triggers client‑certificate validation.
Affected Systems
The flaw affects Fortinet FortiClientEMS across multiple releases, including all 7.2.x versions, the 7.4.0 and 7.4.1 releases, and the 7.4.3 through 7.4.5 releases. These versions are listed as vulnerable in the Fortinet advisory and are included in the affected CPEs.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium severity, suggesting that the breach could result in the disclosure of confidential data but does not grant direct control over the system. EPSS is less than 1%, implying that exploitation in the wild is considered rare but possible. As the vulnerability is not listed in the CISA KEV catalog, there are no confirmed widespread attacks. An attacker could potentially intercept or read confidential data that passes through the client by exploiting the weakened certificate validation, but no public exploit has been documented.
OpenCVE Enrichment