2 results (0.005 seconds)

CVSS: 10.0EPSS: 0%CPEs: 6EXPL: 0

14 Jan 2025 — A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests. • https://fortiguard.com/psirt/FG-IR-23-260 • CWE-321: Use of Hard-coded Cryptographic Key •

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 0

14 Jan 2025 — An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via the FortiSwitch CLI. • https://fortiguard.com/psirt/FG-IR-23-258 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •