CRITICAL

CVE-2023-48788

Fortinet Forticlient Enterprise Management Server 2024-03-12 CVSS v3.1
CVSS
9.8
KEV

Description

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

Summary dbcve.org

SQL injection vulnerability in FortiClientEMS allows remote attackers to execute unauthorized code or commands through specially crafted SQL packets. The vulnerability exists due to improper neutralization of special elements in SQL commands, enabling attackers to inject malicious SQL queries.

Mitigation

Upgrade FortiClientEMS to version 7.2.3 or later (for 7.2.x) or 7.0.11 or later (for 7.0.x). If immediate patching is not possible, restrict network access to the EMS management interface and implement WAF/IPS rules for SQL injection detection.

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

98.45%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE