cbcvebase.
CVE-2023-37936
published 2025-01-14

CVE-2023-37936: A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0…

PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.97%
57.6th percentile
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

Affected

12 ranges
VendorProductVersion rangeFixed in
fortinetfortinet
fortinetfortiswitch
fortinetfortiswitch
fortinetfortiswitch>= 6.0.0 < 6.2.86.2.8
fortinetfortiswitch6.0.0 – 6.0.7
fortinetfortiswitch6.2.0 – 6.2.7
fortinetfortiswitch>= 6.4.0 < 6.4.146.4.14
fortinetfortiswitch6.4.0 – 6.4.13
fortinetfortiswitch>= 7.0.0 < 7.0.87.0.8
fortinetfortiswitch7.0.0 – 7.0.7
fortinetfortiswitch>= 7.2.0 < 7.2.67.2.6
fortinetfortiswitch7.2.0 – 7.2.5

Detection & IOCsextracted from sources · hover to see the quote

  • Look for crafted cryptographic requests targeting FortiSwitch that leverage the hard-coded session secret to achieve unauthenticated remote code execution
  • This vulnerability allows remote, unauthenticated attackers with the hard-coded key to run unauthorized code via crafted cryptographic requests against FortiSwitch devices
  • ·The vulnerability is classified as a hard-coded session secret (CWE-321, CWE-798) with a CVSS score of 9.8 (critical), affecting FortiSwitch across a wide range of versions; patching is the primary remediation
  • ·Affected FortiSwitch versions span multiple major branches: 7.4.0, 7.2.0–7.2.5, 7.0.0–7.0.7, 6.4.0–6.4.13, 6.2.0–6.2.7, and 6.0.0–6.0.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.