{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-48788",
  "revision": 1,
  "title": "FortiClient management server — SQL injection to full control",
  "summary": "The FortiClient endpoint management server (EMS) folds crafted packets into an SQL query, and an attacker who never logged in ends up running commands as the machine's highest account. Versions 7.0.1 to 7.0.10 and 7.2.0 to 7.2.2 are affected.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.98446,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2024-03-25",
    "prerequisites": "Network access to the management server; no credentials are needed."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "FortiClientEMS >= 7.0.11",
      "FortiClientEMS >= 7.2.3"
    ]
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade the endpoint management server to 7.0.11 or 7.2.3, and keep it off the public internet — ransomware crews have walked in through this exact door.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-48788",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-48788",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-48788",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48788",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://fortiguard.com/psirt/FG-IR-24-007"
    }
  ],
  "published_at": "2024-03-12T15:15:46.973Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "fortinet",
    "forticlient",
    "ems",
    "sql-injection",
    "ransomware",
    "kev"
  ]
}
