Fortinet Warns of Yet Another Critical RCE Flaw
ID: ab808f94-8711-5bee-ae81-42e7aeabc0ad
STIX ID: report--ab808f94-8711-5bee-ae81-42e7aeabc0ad
Feed Name: Dark Reading
Fortinet has patched a critical unauthenticated SQL-injection in FortiClient Enterprise Management Server (CVE-2023-48788) that allows remote code execution with system privileges (CVSS ~9.3–9.8); Fortinet recommends upgrading to FortiClientEMS 7.2.3 or 7.0.11 and above. Researchers at Horizon3.ai plan to release technical details, PoCs, and IOCs for this and other Fortinet flaws (several already patched, two reported unpatched), creating a narrow window for organizations to apply fixes before public exploit material appears.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
