← Vulnerability feed

Vulnerability record · CVE-2023-37936 · published 14 January 2025

CVE-2023-37936: Fortinet fortiswitch hard-coded credentials vulnerability

Fortinet · Fortiswitch

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

9.8 CVSS 3.1 Critical EPSS 0.99% · top 38.9% CWE-321 · CWE-321CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score
0.99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-37936 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-48887Fortinet fortiswitch vulnerabilityA unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a sp…EPSS 16%9.8CVE-2023-25610Fortinet fortiweb vulnerabilityA buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0…EPSS 18%9.8CVE-2016-4573Fortinet fortiswitch permissions and access controls vulnerabilityFortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D…EPSS 4.6%9.8CVE-2016-6909Fortinet FortiOS and FortiSwitch Cookie parser buffer overflowThe Cookie parser in Fortinet FortiOS 4.x, 4.2.x and 4.3.x and FortiSwitch before 3.4.3 contains a buffer overflow (CWE-119) reachable through a craf…EPSS 50%analysed8.8CVE-2022-27488Fortinet fortiai cross-site request forgery vulnerabilityA cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4…EPSS 0.49%7.8CVE-2023-37937Fortinet fortiswitch os command injection vulnerabilityAn improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through…EPSS 0.53%7.5CVE-2019-17657Fortinet fortianalyzer uncontrolled resource consumption vulnerabilityAn Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager bel…EPSS 2.4%6.7CVE-2021-42757Fortinet fortiadc classic buffer overflow vulnerabilityA buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local atta…EPSS 0.48%

Source: NIST National Vulnerability Database (record CVE-2023-37936), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.