FortiOS
CVE-2023-37930: Multiple issues including the use of uninitialized ressources in FortiProxy, FortiOS
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| FortiProxy 7.2.0 to 7.2.6 | 7.2.7 or later |
| FortiProxy 7.0.0 to 7.0.12 | 7.0.13 or later |
| FortiOS 7.4 | 7.4.1 or later |
| FortiOS 7.2.0 to 7.2.5 | 7.2.6 or later |
| FortiOS 7.0.1 to 7.0.11 | 7.0.13 or later |
| FortiOS 6.4.7 to 6.4.14 | 6.4.15 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.