Skip to content
COOEY

EXPOSURES › CVE-2023-48788

CVE-2023-48788

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-48788 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

An unauthenticated SQL injection in Fortinet FortiClient EMS allowed attackers to execute SYSTEM commands, leading to ransomware-linked breaches.

Fortinet FortiClient EMS suffered a critical SQL injection flaw enabling unauthenticated attackers to execute SYSTEM commands, directly facilitating ransomware attacks. DIB organizations must ensure this CVE is patched and monitor for similar unpatched, exploited-in-wild vulnerabilities in their supply chain. The failure is highly avoidable through timely patching and highlights the risk of relying on vendors with known, unpatched vulnerabilities.

Shame score — A critical, unauthenticated SQL injection allowing SYSTEM command execution was actively exploited in the wild and linked to ransomware, demonstrating severe negligence and avoidability.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.