cbcvebase.
CVE-2023-37936
published 2025-01-14

CVE-2023-37936: A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

Affected

12 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortiswitch
fortinetfortiswitch
fortinetfortiswitch>= 6.0.0 < 6.2.86.2.8
fortinetfortiswitch6.0.0 – 6.0.7
fortinetfortiswitch6.2.0 – 6.2.7
fortinetfortiswitch>= 6.4.0 < 6.4.146.4.14
fortinetfortiswitch6.4.0 – 6.4.13
fortinetfortiswitch>= 7.0.0 < 7.0.87.0.8
fortinetfortiswitch7.0.0 – 7.0.7
fortinetfortiswitch>= 7.2.0 < 7.2.67.2.6
fortinetfortiswitch7.2.0 – 7.2.5