QID 731291
Date Published: 2024-03-28
QID 731291: FortiClient Endpoint Management Server (EMS) SQL Injection Vulnerability (Unauthenticated Check)
FortiClient Enterprise Management Server (FortiClient EMS) is a security management solution that enables scalable and centralized management of multiple endpoints (computers).
FortiClient EMS is vulnerable to a SQL injection vulnerability, caused by user controlled strings that are passed directly into database queries.
Affected Versions:
FortiClientEMS 7.2.0 - 7.2.2
FortiClientEMS 7.0.1 - 7.0.10
Patched Versions:
FortiClientEMS 7.2.3 or above
FortiClientEMS 7.0.11 or above
QID Detection Logic (Unauthenticated):
These checks for vulnerable FortiClient EMS by sending a crafted payload to the FmcDaemon service. This service is responsible for communicating with enrolled clients. By default, this service listens on port 8013 for incoming client connections. This QID works on the default port (8013) only.
Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted requests.
- FG-IR-24-007 -
www.fortiguard.com/psirt/FG-IR-24-007
CVEs related to QID 731291
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-24-007 |
|