CVE-2023-37930
published 2025-04-08CVE-2023-37930: Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.57%
43.4th percentile
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.7 < 6.4.15 | 6.4.15 |
| fortinet | fortios | 6.4.7 – 6.4.14 | — |
| fortinet | fortios | >= 7.0.1 < 7.0.13 | 7.0.13 |
| fortinet | fortios | 7.0.1 – 7.0.11 | — |
| fortinet | fortios | >= 7.2.0 < 7.2.6 | 7.2.6 |
| fortinet | fortios | 7.2.0 – 7.2.5 | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | >= 7.0.0 < 7.0.13 | 7.0.13 |
| fortinet | fortiproxy | 7.0.0 – 7.0.12 | — |
| fortinet | fortiproxy | >= 7.2.0 < 7.2.7 | 7.2.7 |
| fortinet | fortiproxy | 7.2.0 – 7.2.6 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-48pm-jhrv-8jrv: Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities in Fortinet FortiOS SSL VPN
ghsa_unreviewed·2025-04-08
CVE-2023-37930 [HIGH] CWE-908 GHSA-48pm-jhrv-8jrv: Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities in Fortinet FortiOS SSL VPN
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities in Fortinet FortiOS SSL VPN webmode version 7.4.0, version 7.2.0 through 7.2.5, version 7.0.1 through 7.0.11 and version 6.4.7 through 6.4.14 and Fortinet FortiProxy SSL VPN webmode version 7.2.0 through 7.2.6 and version 7.0.0 through 7.0.12 allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.
Fortinet
Use of uninitialized resource in SSLVPN websocket
vendor_fortinet·2025-04-08·CVSS 7.5
CVE-2023-37930 [HIGH] CWE-908 Use of uninitialized resource in SSLVPN websocket
FG-IR-23-165: Use of uninitialized resource in SSLVPN websocket
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.
CVEs: CVE-2023-37930
CWEs: CWE-908
CVSS: 7.5 (high)
Affected products: FortiOS, FortiProxy, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-08
Published