9.8
CVE-2023-37936
- EPSS 0.24%
- Veröffentlicht 14.01.2025 14:15:26
- Zuletzt bearbeitet 31.01.2025 17:42:50
- Quelle psirt@fortinet.com
- Teams Watchlist Login
- Unerledigt Login
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fortinet ≫ Fortiswitch Version >= 6.0.0 < 6.2.8
Fortinet ≫ Fortiswitch Version >= 6.4.0 < 6.4.14
Fortinet ≫ Fortiswitch Version >= 7.0.0 < 7.0.8
Fortinet ≫ Fortiswitch Version >= 7.2.0 < 7.2.6
Fortinet ≫ Fortiswitch Version7.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.24% | 0.468 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
psirt@fortinet.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-321 Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.