A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortiswitch | Fortinet | 6.0.0 (including) | 6.2.8 (excluding) |
Fortiswitch | Fortinet | 6.4.0 (including) | 6.4.14 (excluding) |
Fortiswitch | Fortinet | 7.0.0 (including) | 7.0.8 (excluding) |
Fortiswitch | Fortinet | 7.2.0 (including) | 7.2.6 (excluding) |
Fortiswitch | Fortinet | 7.4.0 (including) | 7.4.0 (including) |