Vulnerability Details CVE-2023-48786
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.8%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2023-48786
-
cpe:2.3:a:fortinet:forticlientems:6.4.0
-
cpe:2.3:a:fortinet:forticlientems:6.4.1
-
cpe:2.3:a:fortinet:forticlientems:6.4.2
-
cpe:2.3:a:fortinet:forticlientems:6.4.3
-
cpe:2.3:a:fortinet:forticlientems:6.4.4
-
cpe:2.3:a:fortinet:forticlientems:6.4.5
-
cpe:2.3:a:fortinet:forticlientems:6.4.6
-
cpe:2.3:a:fortinet:forticlientems:6.4.7
-
cpe:2.3:a:fortinet:forticlientems:6.4.8
-
cpe:2.3:a:fortinet:forticlientems:6.4.9
-
cpe:2.3:a:fortinet:forticlientems:7.0.0
-
cpe:2.3:a:fortinet:forticlientems:7.0.1
-
cpe:2.3:a:fortinet:forticlientems:7.0.10
-
cpe:2.3:a:fortinet:forticlientems:7.0.11
-
cpe:2.3:a:fortinet:forticlientems:7.0.12
-
cpe:2.3:a:fortinet:forticlientems:7.0.13
-
cpe:2.3:a:fortinet:forticlientems:7.0.2
-
cpe:2.3:a:fortinet:forticlientems:7.0.3
-
cpe:2.3:a:fortinet:forticlientems:7.0.4
-
cpe:2.3:a:fortinet:forticlientems:7.0.5
-
cpe:2.3:a:fortinet:forticlientems:7.0.6
-
cpe:2.3:a:fortinet:forticlientems:7.0.7
-
cpe:2.3:a:fortinet:forticlientems:7.0.8
-
cpe:2.3:a:fortinet:forticlientems:7.0.9
-
cpe:2.3:a:fortinet:forticlientems:7.2.0
-
cpe:2.3:a:fortinet:forticlientems:7.2.1
-
cpe:2.3:a:fortinet:forticlientems:7.2.2
-
cpe:2.3:a:fortinet:forticlientems:7.2.3
-
cpe:2.3:a:fortinet:forticlientems:7.2.4
-
cpe:2.3:a:fortinet:forticlientems:7.2.5
-
cpe:2.3:a:fortinet:forticlientems:7.2.6
-
cpe:2.3:a:fortinet:forticlientems:7.4.0
-
cpe:2.3:a:fortinet:forticlientems:7.4.1