9.8
CVE-2023-37936
- EPSS 0.24%
- Published 14.01.2025 14:15:26
- Last modified 31.01.2025 17:42:50
- Source psirt@fortinet.com
- Teams watchlist Login
- Open Login
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.
Data is provided by the National Vulnerability Database (NVD)
Fortinet ≫ Fortiswitch Version >= 6.0.0 < 6.2.8
Fortinet ≫ Fortiswitch Version >= 6.4.0 < 6.4.14
Fortinet ≫ Fortiswitch Version >= 7.0.0 < 7.0.8
Fortinet ≫ Fortiswitch Version >= 7.2.0 < 7.2.6
Fortinet ≫ Fortiswitch Version7.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.24% | 0.468 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
psirt@fortinet.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-321 Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.