Exploit released for Fortinet RCE bug used in attacks, patch now
ID: bd91a3cf-e4d2-57c3-8626-13bf0760a481
STIX ID: report--bd91a3cf-e4d2-57c3-8626-13bf0760a481
Feed Name: Bleeping Computer
Threat Score
Security researchers disclosed a critical SQL injection vulnerability (CVE-2023-48788) in Fortinet FortiClient EMS (affected 7.0.1–7.0.10 and 7.2.0–7.2.2) that enables unauthenticated actors to achieve remote code execution with SYSTEM privileges; a PoC exploit was published and the vendor has since acknowledged active exploitation while hundreds of EMS instances remain exposed online.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
