CVE-2023-48786

EUVD-2023-52819
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
fortinetCNA
4.1 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
fortinetforticlientems
6.4.0 ≤
𝑥
≤ 6.4.9
fortinetforticlientems
7.0.0 ≤
𝑥
≤ 7.0.13
fortinetforticlientems
7.2.0 ≤
𝑥
< 7.2.7
fortinetforticlientems
7.4.0 ≤
𝑥
< 7.4.3
𝑥
= Vulnerable software versions