CVE Vulnerabilities

CVE-2023-37930

Use of Uninitialized Resource

Published: Apr 08, 2025 | Modified: Jul 23, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities in Fortinet FortiOS SSL VPN webmode version 7.4.0, version 7.2.0 through 7.2.5, version 7.0.1 through 7.0.11 and version 6.4.7 through 6.4.14 and Fortinet FortiProxy SSL VPN webmode version 7.2.0 through 7.2.6 and version 7.0.0 through 7.0.12 allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

Name Vendor Start Version End Version
Fortios Fortinet 6.4.7 (including) 6.4.15 (excluding)
Fortios Fortinet 7.0.1 (including) 7.0.13 (excluding)
Fortios Fortinet 7.2.0 (including) 7.2.6 (excluding)
Fortios Fortinet 7.4.0 (including) 7.4.0 (including)

Potential Mitigations

References