CVE-2023-48788
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
Aktiv ausgenutzt
- Seit dem 25. März 2024 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 15. Apr. 2024 beheben (BOD 22-01)
- Angegriffen 1 Tag bevor die Schwachstelle öffentlich wurde
- In Ransomware-Kampagnen eingesetzt
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Quelle: CISA KEV · 3. Aug. 2026 22. Juli 2026 17. Juni 2026 13. März 2026 10. März 2026 6. März 2026
CVSS-Score9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSchwachstellentyp (CWE)CWE-89
Herstellerfortinet
Betroffene Produkte
| Hersteller | Prodotto | Versioni |
|---|---|---|
| fortinet | forticlient enterprise management server | < 7.0.11 |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
