QID 379522

Date Published: 2024-03-26

QID 379522: FortiClient Endpoint Management Server (EMS) CSV injection Vulnerability (FG-IR-23-390)

FortiClient Enterprise Management Server (FortiClient EMS) is a security management solution that enables scalable and centralized management of multiple endpoints (computers).

Affected Versions:
FortiClientEMS 7.2.0 through 7.2.2
FortiClientEMS 7.0.0 through 7.0.10
FortiClientEMS 6.4 all versions
FortiClientEMS 6.2 all versions
FortiClientEMS 6.0 all versions

QID Detection Logic (Authenticated) :
These checks for vulnerable version of FortiClient EMS through registry key.

Successful exploitation of this vulnerability may allow aremote and unauthenticated attacker to execute arbitrary commands on the admin workstation via creating malicious log entries with crafted requests to the server.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Users are advised to upgrade to the latest version FortiClient EMS 7.2.3 and 7.0.11 or above of the software. Latest version can be downloaded from FG-IR-23-390
    Vendor References

    CVEs related to QID 379522

    Software Advisories
    Advisory ID Software Component Link
    FG-IR-23-390 URL Logo www.fortiguard.com/psirt/FG-IR-23-390