Skip to main content

Critical Vulnerability in FortiSwitch (CVE-2023-37936)

CVSSv3 Score: Base 9.6 Critical

BACKGROUND

Another critical vulnerability addressed by Fortinet is CVE-2023-37936, a hard-coded cryptographic key in Fortinet FortiSwitch. This flaw allows a remote, unauthenticated attacker with access to the hard-coded key to execute unauthorized code via crafted cryptographic requests.

IMPACT 

  • Unauthorized code execution by exploiting the hard-coded cryptographic key flaw.
  • Bypassing authentication mechanisms through crafted cryptographic requests, allowing 
    attackers to gain unauthorized access to the system.
  • Gaining control over FortiSwitch devices, potentially compromising the entire internal 
    network they manage.
  • Attackers can intercept or manipulate sensitive data transmitted through or stored on 
    compromised devices.
  • Attackers can disrupt the network by sending harmful data, changing settings, or shutting 
    down devices using the compromised devices.

AFFECTED PRODUCTS

 ProductAffected Versions
1FortiSwitch 7.47.4.0
2FortiSwitch 7.27.2.0 through 7.2.5
3FortiSwitch 7.07.0.0 through 7.0.7
4FortiSwitch 6.46.4.0 through 6.4.13
5FortiSwitch 6.26.2.0 through 6.2.7
6FortiSwitch 6.06.0.0 through 6.0.7

RECOMMENDATIONS

  • Apply the appropriate updates provided by Fortinet to vulnerable systems after thorough 
    testing.
  • Regularly review system logs and monitor for any unauthorized access or unusual activities.
  • Limit access to management interfaces and ensure they are not exposed to untrusted 
    networks.

REFERENCES

https://www.fortiguard.com/psirt/FG-IR-23-260 

https://www.securityweek.com/fortinet-confirms-new-zero-day-exploitation/

 

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.