Fortinet warns of critical RCE bug in endpoint management software
ID: c5baa3f0-2b0e-514b-8048-e34219f599e0
STIX ID: report--c5baa3f0-2b0e-514b-8048-e34219f599e0
Feed Name: Bleeping Computer
Fortinet patched a critical SQL injection (CVE-2023-48788) in FortiClient EMS that allows unauthenticated remote code execution as SYSTEM on affected 7.0 and 7.2 releases; the flaw was reported by NCSC and Fortinet developers, patches are available, and Horizon3 has announced an upcoming proof-of-concept. The article also highlights additional recent Fortinet fixes (including CVE-2023-42789, CVE-2023-36554, CVE-2023-47534) and references a prior FortiOS/FortiProxy RCE (CVE-2024-21762) that was actively exploited.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
