Fortiswitch
Vendor:
First CVE: Aug 24, 2016 · Active for 9 years
14
Total CVEs
More Total CVEs than 92% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fortiswitch over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2016
9 years ago
Most Recent CVE
Apr 8, 2025
476 days ago
CVE Severity & Scoring
Fortiswitch14 CVEs
43%
21%
36%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (14.3%)
Network10 (71.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (14.3%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (85.7%)
Unknown0 (0.0%)
Required2 (14.3%)
Privileges Required
Low3 (21.4%)
High1 (7.1%)
None10 (71.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6909CRITICAL Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to exec | Aug 24, 2016 | 9.8 | 70 | NO | YES |
CVE-2023-25610CRITICAL A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 t | Mar 24, 2025 | 9.8 | 40 | NO | NO |
CVE-2024-48887CRITICAL A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request | Apr 8, 2025 | 9.8 | 39 | NO | NO |
CVE-2016-4573CRITICAL Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D-FPOE, FSW-448D, FSW-448D-POE, | Sep 9, 2016 | 9.8 | 32 | NO | NO |
CVE-2023-37936CRITICAL A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0 | Jan 14, 2025 | 9.8 | 30 | NO | NO |
CVE-2019-17657HIGH An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below | Apr 7, 2020 | 7.5 | 25 | NO | NO |
CVE-2022-27488HIGH A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x | Dec 13, 2023 | 8.8 | 23 | NO | NO |
CVE-2022-27490MEDIUM A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6. | Mar 7, 2023 | 6.5 | 22 | NO | NO |
CVE-2021-42757MEDIUM A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code | Dec 8, 2021 | 6.7 | 22 | NO | NO |
CVE-2023-37937HIGH An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 | Jan 14, 2025 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Fortiswitch
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.6.0 | 1 | 9.8 | 14.8% | 0 | 0 |
| 7.4.0 | 2 | 8.8 | 0.8% | 0 | 0 |
| 3.4.1 | 1 | 9.8 | 4.6% | 0 | 0 |