fortinet forticlient-enterprise-management-server CVE-2023-48788 is a vulnerability in Fortinet Forticlient Enterprise Management Server
Published on March 12, 2024

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

NVD

Known Exploited Vulnerability

This Fortinet FortiClient EMS SQL Injection Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.

The following remediation steps are recommended / required by April 15, 2024: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Vulnerability Analysis

CVE-2023-48788 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. It has the highest possible exploitability rating (3.9). The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

What is a SQL Injection Vulnerability?

The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

CVE-2023-48788 has been classified to as a SQL Injection vulnerability or weakness.


Products Associated with CVE-2023-48788

You can be notified by stack.watch whenever vulnerabilities like CVE-2023-48788 are published in these products:

 

What versions of Forticlient Enterprise Management Server are vulnerable to CVE-2023-48788?