Known vulnerabilities in FortiSwitch 7.4.0
Vendor:
Fortinet, Inc
Software:
FortiSwitch
Version:
7.4.0
Software CPE:
cpe:2.3:h:fortinet:fortiswitch:*:*:*:*:*:*:*:*
Website:
https://www.fortinet.com/
Total vulnerabilities:
11
Public exploits:
6
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
7.6.8
7.6.7
7.4.12
7.4.10
7.6.6
7.6.5
7.4.9
7.2.12
7.6.4
7.4.7
7.4.8
7.6.2
7.6.3
7.2.11
7.4.6
7.6.1
7.6.0
7.4.5
7.4.4
7.4.3
7.4.2
7.4.1
7.4.0
7.2.10
7.2.9
7.0.14
7.0.13
7.0.12
7.0.11
6.4.15
6.2.11
6.2.10
6.2.9
3.3.0
3.2.2
3.2.1
3.2.0
3.0.1
3.0.0
2.0.3
2.0.2
2.0.1
2.0.0
7.2.8
7.0.10
7.0.9
6.4.14
7.2.7
7.0.8
7.2.6
6.2.8
7.0.7
7.2.5
3.6.12
6.4.13
7.2.4
7.0.6
7.2.3
7.2.2
6.4.12
7.0.5
7.2.1
6.4.11
7.2.0
7.0.4
7.0.3
6.4.10
6.4.9
7.0.2
6.4.8
6.0.7
7.0.1
7.0.0
6.4.7
6.4.6
6.4.5
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.2.7
6.2.6
6.2.5
6.2.4
6.2.3
6.2.2
6.2.1
6.2.0
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
3.6.11
3.6.10
3.6.9
3.6.8
3.6.7
3.6.6
3.6.5
3.6.4
3.6.3
3.6.2
3.6.1
3.6.0
3.5.6
3.5.5
3.5.4
3.5.3
3.5.2
3.5.1
3.5.0
3.4.0
3.3.3
3.3.2
3.3.1
3.4.3
3.4.2
3.4.1
Vulnerabilities (11)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU107318 - Use of Hard-coded Cryptographic Key CVE-2023-37936 |
CWE-321 | Critical | 6.2.8, 6.4.14, 7.0.8, 7.2.6, 7.4.1 | 09.04.2025 |
SB2025040984 |
||
| #VU107317 - Argument Injection or Modification CVE-2023-37937 |
CWE-88 | Low | 6.2.8, 6.4.14, 7.0.8, 7.2.6, 7.4.1 | 09.04.2025 |
SB2025040983 |
||
| #VU107158 - Unverified Password Change CVE-2024-48887 |
CWE-620 | High | 6.4.15, 7.0.11, 7.2.9, 7.4.5, 7.6.1 | 08.04.2025 |
SB2025040849 |
||
| #VU93513 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2024-6387 |
CWE-362 | High | 7.2.9, 7.4.4 | 01.07.2024 |
SB2024070144 SB2024070145 SB2024070152 and 89 more |
||
| #VU88652 - Resource exhaustion CVE-2024-3302 |
CWE-400 | Low | 7.4.4 | 17.04.2024 |
SB2024041746 SB2024041794 SB2024041795 and 34 more |
||
| #VU88184 - Resource exhaustion CVE-2023-45288 |
CWE-400 | Medium | 7.4.4 | 05.04.2024 |
SB2024040533 SB2024040549 SB2024040551 and 187 more |
||
| #VU88181 - Resource exhaustion CVE-2024-30255 |
CWE-400 | Medium | 7.4.4 | 05.04.2024 |
SB2024040530 SB2024100412 SB2024100825 and 2 more |
||
| #VU88175 - Reachable Assertion CVE-2024-27983 |
CWE-617 | Medium | 7.4.4 | 05.04.2024 |
SB2024040526 SB2024040851 SB2024040852 and 56 more |
||
| #VU88153 - Resource exhaustion CVE-2024-27316 |
CWE-400 | Medium | 7.4.4 | 04.04.2024 |
SB2024040458 SB2024040502 SB2024040545 and 51 more |
||
| #VU88144 - Improper input validation CVE-2024-28182 |
CWE-20 | Medium | 7.4.4 | 04.04.2024 |
SB2024040442 SB2024040443 SB2024040444 and 124 more |
||
| #VU87510 - Improper input validation CVE-2024-24549 |
CWE-20 | Medium | 7.4.4 | 13.03.2024 |
SB2024031386 SB2024031879 SB2024031880 and 64 more |