CVE-2023-37935: Fortinet FortiOS

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.

Affected products

  • Fortinet FortiOS: from 7.0.0, up to and including 7.0.12; from 7.2.0, up to and including 7.2.5; version 7.4.0 only

Published 2023-10-10. Last modified 2026-06-17.