First published: Tue Sep 10 2024(Updated: )
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiClient Enterprise Management Server | >=7.0.0<7.0.13 | |
Fortinet FortiClient Enterprise Management Server | >=7.2.0<7.2.5 |
Please upgrade to FortiSASE version 24.2.c or above Please upgrade to FortiClientEMS version 7.4.0 or above Please upgrade to FortiClientEMS version 7.2.5 or above Please upgrade to FortiClientEMS version 7.0.13 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.