SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Fortinet Fixes Actively Exploited FORTICLIENT EMS Flaw Allowing Unauthorised Code Execution

Fortinet Fixes Actively Exploited FORTICLIENT EMS Flaw Allowing Unauthorised Code Execution

Fortinet has issued an advisory warning about a new critical vulnerability in Fortinet’s FortiClient Enterprise Management Server (EMS) software. This flaw, identified as CVE-2023-48788, has been assigned a severity score of 9.3 on the CVSS scale, underlining its potential for serious impact. Horizo...

Mar 21, 2024By Muqsit Mamdu3 min read

Fortinet has issued an advisory warning about a new critical vulnerability in Fortinet’s FortiClient Enterprise Management Server (EMS) software. This flaw, identified as CVE-2023-48788, has been assigned a severity score of 9.3 on the CVSS scale, underlining its potential for serious impact. Horizon3, a prominent team of security researchers, has disclosed a proof-of-concept (PoC) exploit, indicating that the vulnerability is theoretical and being actively exploited in real-world attacks. The Nature of the Vulnerability

CVE-2023-48788 is a critical SQL injection flaw located within the DAS component of FortiClientEMS. The vulnerability stems from the software’s improper neutralization of particular elements used in SQL commands. This oversight allows an unauthenticated attacker to execute unauthorized code or commands through specially crafted requests. Exploiting this flaw can lead to complete system compromise data breaches, potentially enabling attackers to gain a foothold within the affected organization’s network.

Affected Versions and Remediation

The issue was initially reported by Thiago Santana from the FortiClientEMS development team and the UK National Cyber Security Centre (NCSC), prompting swift action by Fortinet to address this critical flaw.

Updated Advisory: Exploited in the Wild

Although Fortinet’s initial advisory reported no known instances of exploitation, the company has since updated its advisory to confirm that CVE-2023-48788 is indeed being exploited in active attacks. This revelation underscores the urgency for administrators to apply the necessary patches to mitigate the risk.

Technical Analysis and Indicators of Compromise

Horizon3’s Attack Team has published a detailed technical analysis of the vulnerability and a PoC exploit. Their findings show that while the database’s default configuration does not enable the xp_cmdshell command (often used for remote code execution), attackers could still execute it through additional SQL statements.

Administrators are advised to inspect various log files, particularly those located in C:\Program Files (x86)\Fortinet\FortiClientEMS\logs, for any signs of unauthorized access or other indicators of compromise. The Microsoft SQL logs should also be reviewed for any evidence of the xp_cmdshell command being executed, which could indicate a successful exploitation.

Action Required

Given the severity of CVE-2023-48788 and its active exploitation, it is crucial for organizations running the affected versions of FortiClientEMS to upgrade to the patched versions immediately. Fortinet has also provided a virtual patch, “FG-VD-54509.0day:FortiClientEMS.DAS.SQL.Injection”, available in FMWP database update 27.750, as a temporary measure for those unable to upgrade immediately.

Have any questions on how to fix CVE-2023-48788 specific to your IT? Let’s discuss.

JOIN SECPOD COMMUNITY

Featured Posts

Open StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores
StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

CVE Research

StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

StyleSmuggler, an unpatched Magento and Adobe Commerce flaw letting attackers execute code without authentication via log poisoning, installing a persistent Linux backdoor that has already compromised live stores with no vendor patch available.

Sep 7, 2026

Open CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover
CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Vulnerability

CVE Research

CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover

Sep 7, 2026

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026