EXPOSURES › CVE-2023-48788
CVE-2023-48788
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated SQL injection in Fortinet FortiClient EMS allowed attackers to execute SYSTEM commands, leading to ransomware-linked breaches.
Fortinet FortiClient EMS suffered a critical SQL injection flaw enabling unauthenticated attackers to execute SYSTEM commands, directly facilitating ransomware attacks. DIB organizations must ensure this CVE is patched and monitor for similar unpatched, exploited-in-wild vulnerabilities in their supply chain. The failure is highly avoidable through timely patching and highlights the risk of relying on vendors with known, unpatched vulnerabilities.
Shame score — A critical, unauthenticated SQL injection allowing SYSTEM command execution was actively exploited in the wild and linked to ransomware, demonstrating severe negligence and avoidability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.