CVE-2023-37930: Use of uninitialized resource in SSLVPN websocket
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.
Other sources
Multiple potential issues, including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] in FortiOS & FortiProxy SSLVPN webmode may allow a VPN user to corrupt memory, potentially leading to code or commands execution via specifically crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37930?
CVE-2023-37930 has been assigned a high severity rating due to its potential to allow unauthorized access and system compromise.
How do I fix CVE-2023-37930?
To fix CVE-2023-37930, users should upgrade FortiOS SSL VPN webmode to version 7.4.1 or later and FortiProxy SSL VPN webmode to version 7.2.6 or later.
Which versions are affected by CVE-2023-37930?
CVE-2023-37930 affects FortiOS SSL VPN webmode versions 6.4.7 to 6.4.14, 7.0.1 to 7.0.11, and 7.2.0 to 7.2.5, as well as FortiProxy SSL VPN webmode versions 7.0.0 to 7.0.12 and 7.2.0 to 7.2.6.
What vulnerabilities are included in CVE-2023-37930?
CVE-2023-37930 includes vulnerabilities such as the use of uninitialized resources and excessive iteration, which can be exploited for denial of service and data compromise.
Who is impacted by CVE-2023-37930?
Organizations using the affected versions of Fortinet FortiOS SSL VPN webmode and FortiProxy SSL VPN webmode are at risk due to CVE-2023-37930.