March 14, 2024, 6:19 p.m. | Chris Boyd

Cyber Exposure Alerts www.tenable.com

Fortinet warns of a critical SQL Injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code on vulnerable FortiClientEMS software.

Background

On March 12, Fortinet published an advisory (FG-IR-24-007) to address a critical flaw in its FortiClient Enterprise Management Server (FortiClientEMS), a solution which enables centralized management of multiple endpoints.

CVEDescriptionCVSSv3SeverityCVE-2023-48788Critical SQL Injection Vulnerability (or Improper neutralization of special elements in an SQL command)9.3Critical

At the time this blog was published, …

address advisory arbitrary code attacker centralized management code critical critical flaw cve endpoints enterprise flaw fortinet injection management march server software solution sql sql injection unauthenticated vulnerability vulnerable

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Officer Hospital Laguna Beach

@ Allied Universal | Laguna Beach, CA, United States

Sr. Cloud DevSecOps Engineer

@ Oracle | NOIDA, UTTAR PRADESH, India

Cloud Operations Security Engineer

@ Elekta | Crawley - Cornerstone

Cybersecurity – Senior Information System Security Manager (ISSM)

@ Boeing | USA - Seal Beach, CA

Engineering -- Tech Risk -- Security Architecture -- VP -- Dallas

@ Goldman Sachs | Dallas, Texas, United States