Vulnerability Details CVE-2023-48786
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.2%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2023-48786
-
cpe:2.3:a:fortinet:forticlientems:6.4.0
-
cpe:2.3:a:fortinet:forticlientems:6.4.1
-
cpe:2.3:a:fortinet:forticlientems:6.4.2
-
cpe:2.3:a:fortinet:forticlientems:6.4.3
-
cpe:2.3:a:fortinet:forticlientems:6.4.4
-
cpe:2.3:a:fortinet:forticlientems:6.4.5
-
cpe:2.3:a:fortinet:forticlientems:6.4.6
-
cpe:2.3:a:fortinet:forticlientems:6.4.7
-
cpe:2.3:a:fortinet:forticlientems:6.4.8
-
cpe:2.3:a:fortinet:forticlientems:6.4.9
-
cpe:2.3:a:fortinet:forticlientems:7.0.0
-
cpe:2.3:a:fortinet:forticlientems:7.0.1
-
cpe:2.3:a:fortinet:forticlientems:7.0.10
-
cpe:2.3:a:fortinet:forticlientems:7.0.11
-
cpe:2.3:a:fortinet:forticlientems:7.0.12
-
cpe:2.3:a:fortinet:forticlientems:7.0.13
-
cpe:2.3:a:fortinet:forticlientems:7.0.2
-
cpe:2.3:a:fortinet:forticlientems:7.0.3
-
cpe:2.3:a:fortinet:forticlientems:7.0.4
-
cpe:2.3:a:fortinet:forticlientems:7.0.5
-
cpe:2.3:a:fortinet:forticlientems:7.0.6
-
cpe:2.3:a:fortinet:forticlientems:7.0.7
-
cpe:2.3:a:fortinet:forticlientems:7.0.8
-
cpe:2.3:a:fortinet:forticlientems:7.0.9
-
cpe:2.3:a:fortinet:forticlientems:7.2.0
-
cpe:2.3:a:fortinet:forticlientems:7.2.1
-
cpe:2.3:a:fortinet:forticlientems:7.2.2
-
cpe:2.3:a:fortinet:forticlientems:7.2.3
-
cpe:2.3:a:fortinet:forticlientems:7.2.4
-
cpe:2.3:a:fortinet:forticlientems:7.2.5
-
cpe:2.3:a:fortinet:forticlientems:7.2.6
-
cpe:2.3:a:fortinet:forticlientems:7.4.0
-
cpe:2.3:a:fortinet:forticlientems:7.4.1