Overview
- Description
- A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Known exploits
Data from CISA
- Vulnerability name
- Fortinet FortiClient EMS SQL Injection Vulnerability
- Exploit added on
- Mar 25, 2024
- Exploit action due
- Apr 15, 2024
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Weaknesses
- psirt@fortinet.com
- CWE-89
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA97EA36-75D0-40DA-98CD-4C94E061A28F", "versionEndIncluding": "7.0.10", "versionStartIncluding": "7.0.1" }, { "criteria": "cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C4BC53A-0E69-4CDE-B89A-E6AAC3ADB1E0", "versionEndIncluding": "7.2.2", "versionStartIncluding": "7.2.0" } ], "operator": "OR" } ] } ]