CVE-2024-33508
published 2024-09-10CVE-2024-33508: An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4…
PriorityP351high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
1.29%
66.8th percentile
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient_enterprise_management_server | >= 7.0.0 < 7.0.13 | 7.0.13 |
| fortinet | forticlient_enterprise_management_server | >= 7.2.0 < 7.2.5 | 7.2.5 |
| fortinet | forticlientems | — | — |
| fortinet | forticlientems | 7.0.0 – 7.0.12 | — |
| fortinet | forticlientems | 7.2.0 – 7.2.4 | — |
| fortinet | forticliententerprisemanagementserver | — | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jr6g-3qr2-xfh3: An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7
ghsa_unreviewed·2024-09-10
CVE-2024-33508 [HIGH] CWE-77 GHSA-jr6g-3qr2-xfh3: An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.
Fortinet
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortine...
vendor_fortinet·2024-09-10·CVSS 7.3
CVE-2024-33508 [HIGH] CWE-77 An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortine...
FG-IR-24-123: An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortine...
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.
CVEs: CVE-2024-33508
CWEs: CWE-77
CVSS: 7.3 (high)
Affected products: FortiClientEMS, FortiCliententerprisemanagementserver, Fortinet
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21643 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-21643 [CRITICAL] CVE-2026-21643 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21643 :
FortiClient EMS vulnerability analysis and mitigation
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Source : NVD
## 9.8
Score
Published February 6, 2026
Severity CRITICAL
CNA Score 9.8
Affected Technologies
FortiClient EMS
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.6
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient_endpoint_management_server
Sources
Windows Severity CRITICAL Has Fix Added at: Feb 11
Wiz
CVE-2026-35616 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-35616 [CRITICAL] CVE-2026-35616 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-35616 :
FortiClient EMS vulnerability analysis and mitigation
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Source : NVD
## 9.8
Score
Published April 4, 2026
Severity CRITICAL
CNA Score 9.8
High-profile Vulnerability Yes
Affected Technologies
FortiClient EMS
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 90.6
Exploitation Probability (EPSS) 6
Affected packages and libraries
cpe:2.3:a:fortinet:forticlient_enterprise_management_server
Sources
Windows Severity CRITICAL Has Fix Added at: Apr 05, 2026
## Get a CVE risk assessmen
2024-09-10
Published