CVE-2023-48788
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 25 mar 2024
- Le agenzie federali statunitensi devono correggerla entro il 15 apr 2024 (direttiva BOD 22-01)
- Attaccata 1 giorno prima che la vulnerabilità fosse resa pubblica
- Usata in campagne ransomware
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Fonte: CISA KEV · 3 ago 2026 22 lug 2026 17 giu 2026 13 mar 2026 10 mar 2026 6 mar 2026
Punteggio CVSS9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTipo di debolezza (CWE)CWE-89
Vendorfortinet
Prodotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| fortinet | forticlient enterprise management server | < 7.0.11 |
Articoli correlati
This product uses the NVD API but is not endorsed or certified by the NVD.
