← Vulnerability feed

Vulnerability record · CVE-2023-48788 · published 12 March 2024

CVE-2023-48788: FortiClient EMS SQL injection allows unauthenticated remote code execution

Fortinet · Forticlient Enterprise Management Server

FortiClient Enterprise Management Server (EMS) versions 7.2.0 through 7.2.2 and 7.0.1 through 7.0.10 fail to neutralize special elements in SQL commands, allowing SQL injection through specially crafted packets. The flaw is remotely reachable without authentication and can lead to execution of unauthorized code or commands, making it a serious risk to exposed management servers.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2024 Known ransomware use EPSS 98% · top 0.1% CWE-89 · SQL injection
9.8CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network reachability, active exploitation in CISA KEV with ransomware use, and near-maximum EPSS probability make this an urgent patch.

What it is

FortiClient Enterprise Management Server (EMS) versions 7.2.0 through 7.2.2 and 7.0.1 through 7.0.10 fail to neutralize special elements in SQL commands, allowing SQL injection through specially crafted packets. The flaw is remotely reachable without authentication and can lead to execution of unauthorized code or commands, making it a serious risk to exposed management servers.

Impact

An unauthenticated attacker can inject SQL and execute unauthorized code or commands on the EMS server, potentially compromising the management platform and any endpoints it manages.

Attack surface

Reached over the network via specially crafted packets to the EMS service; the CVSS vector shows no privileges required and no user interaction. No further detail on the exact endpoint or protocol is provided in the record.

Exploitation

Listed in CISA KEV with a due date of 2024-04-15 and flagged for known ransomware campaign use, and EPSS 30-day probability is 0.98446 (99.9th percentile), indicating active exploitation.

What to do

  • Apply the Fortinet vendor fix per FG-IR-24-007 for the affected FortiClient EMS versions.
  • If patching is not immediately possible, restrict network access to the EMS management interface to trusted hosts only.
  • Discontinue use of the product if vendor mitigations cannot be applied, as directed by CISA KEV.
  • Review EMS server logs and database activity for signs of injected SQL or unexpected command execution.
  • Isolate or rebuild any EMS server suspected of compromise before restoring management functions.

Detection

  • Monitor EMS server and database logs for SQL syntax errors, unusual query patterns, or injected SQL keywords.
  • Alert on unexpected outbound connections or process creation on the EMS host.
  • Hunt for anomalous authentication or request patterns against the EMS management interface from untrusted sources.
  • Correlate network traffic to EMS with known exploitation attempts or scanning activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-48788 to the Known Exploited Vulnerabilities catalog on 25 March 2024 as "Fortinet FortiClient EMS SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 15 April 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-48788 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2021-41030Fortinet forticlient enterprise management server authentication bypass by capture-replay vulnerabilityAn authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unaut…EPSS 0.96%7.8CVE-2021-32592Fortinet forticlient uncontrolled search path element vulnerabilityAn unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.…EPSS 0.25%7.3CVE-2024-33508Fortinet forticlient enterprise management server command injection vulnerabilityAn improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 throug…EPSS 1.3%7.2CVE-2023-45581Fortinet forticlient enterprise management server improper privilege management vulnerabilityAn improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site admi…EPSS 0.82%5.4CVE-2020-15940Fortinet forticlient enterprise management server cross-site scripting vulnerabilityAn improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenti…EPSS 0.74%4.9CVE-2021-36189Fortinet forticlient enterprise management server missing encryption vulnerabilityA missing encryption of sensitive data in Fortinet FortiClientEMS version 7.0.1 and below, version 6.4.4 and below allows attacker to information dis…EPSS 0.39%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2023-48788), CISA KEV, FIRST EPSS (scores of 2026-09-21). This page is refreshed as NVD updates the record.