CVE-2023-48788
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Mar 25, 2024
- US federal agencies must remediate it by Apr 15, 2024 (BOD 22-01)
- Attacked 1 day before the vulnerability was made public
- Used in ransomware campaigns
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Aug 3, 2026 Jul 22, 2026 Jun 17, 2026 Mar 13, 2026 Mar 10, 2026 Mar 6, 2026
CVSS score9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeakness type (CWE)CWE-89
Vendorsfortinet
Affected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| fortinet | forticlient enterprise management server | < 7.0.11 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
