216.73.217.22

CVE-2023-37936

· Published 14/01/2025 14:15 · Modified 31/01/2025 17:42

Labels: CVE-2023-37936 2025-01-14CVE-2023-37936CWE-321CWE-798[email protected]

Essential information

Published
14/01/2025 14:15
Modified
31/01/2025 17:42
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
fortinet / fortiswitch cpe:2.3:o:fortinet:fortiswitch:*:*:*:*:*:*:*:*
fortinet / fortiswitch cpe:2.3:o:fortinet:fortiswitch:*:*:*:*:*:*:*:*
fortinet / fortiswitch cpe:2.3:o:fortinet:fortiswitch:*:*:*:*:*:*:*:*
fortinet / fortiswitch cpe:2.3:o:fortinet:fortiswitch:*:*:*:*:*:*:*:*
fortinet / fortiswitch cpe:2.3:o:fortinet:fortiswitch:7.4.0:*:*:*:*:*:*:*

References