• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
fortinet warns of severe sqli vulnerability in forticlientems software

Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS Software

You are here: Home / General Cyber Security News / Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS Software
March 14, 2024

Fortinet has warned of a critical security flaw impacting its FortiClientEMS computer software that could allow for attackers to realize code execution on affected methods.

“An incorrect neutralization of unique things used in an SQL Command (‘SQL Injection’) vulnerability [CWE-89] in FortiClientEMS may well enable an unauthenticated attacker to execute unauthorized code or commands by way of specially crafted requests,” the business reported in an advisory.

The vulnerability, tracked as CVE-2023-48788, carries a CVSS score of 9.3 out of a maximum of 10. It impacts the adhering to versions –

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


  • FortiClientEMS 7.2. as a result of 7.2.2 (Upgrade to 7.2.3 or earlier mentioned)
  • FortiClientEMS 7..1 by 7..10 (Enhance to 7..11 or over)

Horizon3.ai, which plans to launch added technological information and a proof-of-notion (PoC) exploit next 7 days, reported the shortcoming could be exploited to receive distant code execution as Method on the server.

Cybersecurity

Fortinet has credited Thiago Santana From the ForticlientEMS progress staff and the U.K. Countrywide Cyber Security Centre (NCSC) for discovering and reporting the flaw.

Also mounted by the company two other critical bugs in FortiOS and FortiProxy (CVE-2023-42789 and CVE-2023-42790, CVSS scores: 9.3) that could allow an attacker with accessibility to the captive portal to execute arbitrary code or commands by means of specifically crafted HTTP requests.

The underneath product or service versions are impacted by the flaws –

  • FortiOS variation 7.4. by 7.4.1 (Improve to FortiOS version 7.4.2 or over)
  • FortiOS version 7.2. by 7.2.5 (Update to FortiOS edition 7.2.6 or above)
  • FortiOS edition 7.. through 7..12 (Enhance to FortiOS edition 7..13 or above)
  • FortiOS edition 6.4. by way of 6.4.14 (Update to FortiOS variation 6.4.15 or over)
  • FortiOS variation 6.2. by way of 6.2.15 (Improve to FortiOS edition 6.2.16 or above)
  • FortiProxy variation 7.4. (Up grade to FortiProxy variation 7.4.1 or above)
  • FortiProxy variation 7.2. by way of 7.2.6 (Upgrade to FortiProxy version 7.2.7 or higher than)
  • FortiProxy version 7.. by means of 7..12 (Up grade to FortiProxy model 7..13 or earlier mentioned)
  • FortiProxy variation 2.. as a result of 2..13 (Up grade to FortiProxy variation 2..14 or over)

Whilst there is no proof that the aforementioned flaws have occur under energetic exploitation, unpatched Fortinet appliances have been regularly abused by menace actors, earning it crucial that people shift rapidly to apply the updates.

Discovered this write-up fascinating? This post is a contributed piece from just one of our valued partners. Follow us on Twitter  and LinkedIn to go through much more exceptional information we write-up.


Some pieces of this report are sourced from:
thehackernews.com

Previous Post: «demystifying a common cybersecurity myth Demystifying a Common Cybersecurity Myth
Next Post: DarkGate Malware Exploits Recently Patched Microsoft Flaw in Zero-Day Attack darkgate malware exploits recently patched microsoft flaw in zero day attack»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.