QID 379512
Date Published: 2024-03-18
QID 379512: FortiClient Endpoint Management Server (EMS) SQL Injection Vulnerability (FG-IR-24-007)
FortiClient Enterprise Management Server (FortiClient EMS) is a security management solution that enables scalable and centralized management of multiple endpoints (computers).
Affected Versions:
FortiClientEMS 7.2.0 through 7.2.2
FortiClientEMS 7.0.1 through 7.0.10
QID Detection Logic (Authenticated) :
These checks for vulnerable version of FortiClient EMS through registry key.
Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted requests.
Solution
Users are advised to upgrade to the latest version FortiClient EMS 7.2.3 and 7.0.11 or above of the software. Latest version can be downloaded from FG-IR-24-007
Vendor References
- FG-IR-24-007 -
www.fortiguard.com/psirt/FG-IR-24-007
CVEs related to QID 379512
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-24-007 |
|