Executive brief
A SQL injection vulnerability in Fortinet FortiClient EMS allows an unauthenticated remote attacker to execute unauthorized code or commands via specially crafted packets. The flaw stems from improper neutralization of special elements used in SQL commands.
Affected products
- Fortinet FortiClientEMS 7.2.0 through 7.2.2, 7.0.1 through 7.0.10
Timeline
- 2024-03-12: disclosed: Initial disclosure by Fortinet
- 2024-03-12: advisory: NVD publication date
- 2024-03-25: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2024-03-25: exploited: Reported as exploited in the wild