PT-2025-24706 · Fortinet · Forticlientems

Published

2025-06-10

·

Updated

2025-06-10

·

CVE-2023-48786

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiClientEMS versions 7.4.0 through 7.4.2 Fortinet FortiClientEMS versions prior to 7.2.6
Description A server-side request forgery issue may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.
Recommendations For Fortinet FortiClientEMS versions 7.4.0 through 7.4.2, update to a version outside of this range to resolve the issue. For Fortinet FortiClientEMS versions prior to 7.2.6, update to version 7.2.6 or later to resolve the issue.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2025-12650
CVE-2023-48786

Affected Products

Forticlientems