CVE-2023-48788

CRITICAL9.8Pubblicata il 12 marzo 2024

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

Sfruttata attivamente

  • Nel catalogo CISA delle vulnerabilità sfruttate dal 25 mar 2024
  • Le agenzie federali statunitensi devono correggerla entro il 15 apr 2024 (direttiva BOD 22-01)
  • Attaccata 1 giorno prima che la vulnerabilità fosse resa pubblica
  • Usata in campagne ransomware

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Fonte: CISA KEV · 3 ago 2026 22 lug 2026 17 giu 2026 13 mar 2026 10 mar 2026 6 mar 2026

Punteggio CVSS9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-89
Vendorfortinet

Prodotti coinvolti

VendorProdottoVersioni
fortinetforticlient enterprise management server< 7.0.11

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE