Vulnerability threat dossier

CVE-2023-48788

fortinetforticlient enterprise management server

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

VTP deterministic threat61.7of 100 · CVSS excluded

VTP analyst assessment

FortiClient EMS SQL injection

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

Critical unauthenticated SQL injection in affected FortiClient EMS versions. CISA KEV and ENISA EU KEV establish known global exploitation; CISA also records known ransomware-campaign use. This is public intelligence, not VTP observation.

Why it matters

  • Specially crafted packets may allow unauthorized command or code execution on the EMS server.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

Affected version presence and patch status are unknown.

No VTP sensor evidence is supplied.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Identify FortiClient EMS 7.2.0-7.2.2 and 7.0.1-7.0.10.

AI baseline history (3)
  1. BASELINE ASSESSED
    FortiClient EMS SQL injectiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    FortiClient EMS SQL injectiongpt-5.6-sol · high
  3. BASELINE ASSESSED
    FortiClient EMS unauthenticated SQL injection in KEVgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.98100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.98; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

1 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2023-48788ACTIVE
Evidence
04

Event history

Threat timeline

  1. 00:0025 Mar
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

  2. 00:0025 Mar
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

05

Original publications

Source record

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted

CVE-2023-37679CVE-2023-43208CVE-2023-48788CVE-2024-1708CVE-2024-1709CVE-2024-27198CVE-2024-27199CVE-2025-10035CVE-2026-18556CVE-2026-18577
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2023-48788

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2023-48788
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score61.7vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.69 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-89
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.