CVE Vulnerabilities

CVE-2023-37930

Use of Uninitialized Resource

Published: Apr 08, 2025 | Modified: Jan 14, 2026
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
FortiosFortinet6.4.7 (including)6.4.15 (excluding)
FortiosFortinet7.0.1 (including)7.0.13 (excluding)
FortiosFortinet7.2.0 (including)7.2.6 (excluding)
FortiosFortinet7.4.0 (including)7.4.0 (including)

Potential Mitigations

References