CVE-2023-37936: Fortinet Fortiswitch

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

Affected products

  • Fortinet Fortiswitch: from 6.0.0, before 6.2.8 (fixed in 6.2.8); from 6.4.0, before 6.4.14 (fixed in 6.4.14); from 7.0.0, before 7.0.8 (fixed in 7.0.8); from 7.2.0, before 7.2.6 (fixed in 7.2.6); version 7.4.0 only

Published 2025-01-14. Last modified 2026-06-17.