SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Fortinet Fixes Actively Exploited FORTICLIENT EMS Flaw Allowing Unauthorised Code Execution

Fortinet Fixes Actively Exploited FORTICLIENT EMS Flaw Allowing Unauthorised Code Execution

Fortinet has issued an advisory warning about a new critical vulnerability in Fortinet’s FortiClient Enterprise Management Server (EMS) software. This flaw, identified as CVE-2023-48788, has been assigned a severity score of 9.3 on the CVSS scale, underlining its potential for serious impact. Horizo...

Mar 21, 2024By Muqsit Mamdu3 min read

Fortinet has issued an advisory warning about a new critical vulnerability in Fortinet’s FortiClient Enterprise Management Server (EMS) software. This flaw, identified as CVE-2023-48788, has been assigned a severity score of 9.3 on the CVSS scale, underlining its potential for serious impact. Horizon3, a prominent team of security researchers, has disclosed a proof-of-concept (PoC) exploit, indicating that the vulnerability is theoretical and being actively exploited in real-world attacks. The Nature of the Vulnerability

CVE-2023-48788 is a critical SQL injection flaw located within the DAS component of FortiClientEMS. The vulnerability stems from the software’s improper neutralization of particular elements used in SQL commands. This oversight allows an unauthenticated attacker to execute unauthorized code or commands through specially crafted requests. Exploiting this flaw can lead to complete system compromise data breaches, potentially enabling attackers to gain a foothold within the affected organization’s network.

Affected Versions and Remediation

The issue was initially reported by Thiago Santana from the FortiClientEMS development team and the UK National Cyber Security Centre (NCSC), prompting swift action by Fortinet to address this critical flaw.

Updated Advisory: Exploited in the Wild

Although Fortinet’s initial advisory reported no known instances of exploitation, the company has since updated its advisory to confirm that CVE-2023-48788 is indeed being exploited in active attacks. This revelation underscores the urgency for administrators to apply the necessary patches to mitigate the risk.

Technical Analysis and Indicators of Compromise

Horizon3’s Attack Team has published a detailed technical analysis of the vulnerability and a PoC exploit. Their findings show that while the database’s default configuration does not enable the xp_cmdshell command (often used for remote code execution), attackers could still execute it through additional SQL statements.

Administrators are advised to inspect various log files, particularly those located in C:\Program Files (x86)\Fortinet\FortiClientEMS\logs, for any signs of unauthorized access or other indicators of compromise. The Microsoft SQL logs should also be reviewed for any evidence of the xp_cmdshell command being executed, which could indicate a successful exploitation.

Action Required

Given the severity of CVE-2023-48788 and its active exploitation, it is crucial for organizations running the affected versions of FortiClientEMS to upgrade to the patched versions immediately. Fortinet has also provided a virtual patch, “FG-VD-54509.0day:FortiClientEMS.DAS.SQL.Injection”, available in FMWP database update 27.750, as a temporary measure for those unable to upgrade immediately.

Have any questions on how to fix CVE-2023-48788 specific to your IT? Let’s discuss.

JOIN SECPOD COMMUNITY

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026