CVE Vulnerabilities

CVE-2023-37936

Use of Hard-coded Cryptographic Key

Published: Jan 14, 2025 | Modified: Jan 31, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

Weakness

The product uses a hard-coded, unchangeable cryptographic key.

Affected Software

NameVendorStart VersionEnd Version
FortiswitchFortinet6.0.0 (including)6.2.8 (excluding)
FortiswitchFortinet6.4.0 (including)6.4.14 (excluding)
FortiswitchFortinet7.0.0 (including)7.0.8 (excluding)
FortiswitchFortinet7.2.0 (including)7.2.6 (excluding)
FortiswitchFortinet7.4.0 (including)7.4.0 (including)

Potential Mitigations

References