CVE-2023-48788

CRITICAL9.8Published on March 12, 2024

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Mar 25, 2024
  • US federal agencies must remediate it by Apr 15, 2024 (BOD 22-01)
  • Attacked 1 day before the vulnerability was made public
  • Used in ransomware campaigns

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Source: CISA KEV · Aug 3, 2026 Jul 22, 2026 Jun 17, 2026 Mar 13, 2026 Mar 10, 2026 Mar 6, 2026

CVSS score9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-89
Vendorsfortinet

Affected products

VendorsProdottoVersioni
fortinetforticlient enterprise management server< 7.0.11

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database