Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-37936


A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.


Published

2025-01-14T14:15:26.790

Last Modified

2025-01-31T17:42:50.520

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-321
  • Type: Primary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System fortinet fortiswitch < 6.2.8 Yes
Operating System fortinet fortiswitch < 6.4.14 Yes
Operating System fortinet fortiswitch < 7.0.8 Yes
Operating System fortinet fortiswitch < 7.2.6 Yes
Operating System fortinet fortiswitch 7.4.0 Yes

References