CVE-2023-48788

CVE Published 2024-03-12
Related CWE(s) CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Related Vendor(s) fortinet
Related Product(s) forticlient_enterprise_management_server
Exploitation Reported (CISA KEV) 2024-03-25
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2023-48788

Report

Connect:fun Detailing an exploitation campaign targeting FortiClient EMS via CVE-2023-48788

This report from Vedere Labs at Forescout Research details an exploitation campaign which they have designated Connect:fun. The attacks exploit ...

Report

Holding down the Fortinet vulnerability

This report from Red Canary outlines activity they have observed related to the exploitation of CVE-2023-48788 in FortiClient enterprise ...

Associated CAPEC Patterns

References