7.5
CVSSv3

CVE-2023-37930

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: NA | VMScore: 850 | EPSS: 0.00114 | KEV: Not Included
Published: 08/04/2025 Updated: 08/04/2025

Vulnerability Summary

Multiple Memory Corruption Vulnerabilities in Fortinet FortiOS and FortiProxy SSL VPN

Fortinet FortiOS and FortiProxy SSL VPN webmode are vulnerable to memory corruption issues across multiple versions. Uninitialized resources and excessive iteration flaws exist in FortiOS SSL VPN versions 7.4.0, 7.2.0 through 7.2.5, 7.0.1 through 7.0.11, and 6.4.7 through 6.4.14, as well as FortiProxy SSL VPN versions 7.2.0 through 7.2.6 and 7.0.0 through 7.0.12. These vulnerabilities can allow a VPN user to corrupt memory, potentially enabling code or command execution through specially crafted requests. The issues are related to CWE-908 (Use of Uninitialized Resource) and CWE-834 (Excessive Iteration) and could pose significant security risks for affected systems.

Solution

Please upgrade to FortiOS version 7.4.1 or above
Please upgrade to FortiOS version 7.2.6 or above
Please upgrade to FortiOS version 7.0.13 or above
Please upgrade to FortiOS version 6.4.15 or above
Please upgrade to FortiOS version 6.4.14 or above
Please upgrade to FortiProxy version 7.4.0 or above
Please upgrade to FortiProxy version 7.2.7 or above
Please upgrade to FortiProxy version 7.0.13 or above

FortiSASE is no longer impacted, issue remediated Q3/23

## Workaround:


Disable SSLVPN webmode.

Alternatively, please use SSLVPN tunnel mode, IPsec (tunnel) or ZTNA (web access).

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-disable-SSL-VPN-Web-Mode-or-Tunnel-Mode-in/ta-p/217990

https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/45836/ssl-vpn-to-ipsec-vpn

https://docs.fortinet.com/document/fortigate/7.2.3/administration-guide/78050/migrating-from-ssl-vpn-to-ztna
Vulnerable Product Search on Vulmon Subscribe to Product

fortinet fortios 7.4.0

fortinet fortios 7.2.5

fortinet fortios 7.2.4

fortinet fortios 7.2.3

fortinet fortios 7.2.2

fortinet fortios 7.2.1

fortinet fortios 7.2.0

fortinet fortios 7.0.11

fortinet fortios 7.0.10

fortinet fortios 7.0.9

fortinet fortios 7.0.8

fortinet fortios 7.0.7

fortinet fortios 7.0.6

fortinet fortios 7.0.5

fortinet fortios 7.0.4

fortinet fortios 7.0.3

fortinet fortios 7.0.2

fortinet fortios 7.0.1

fortinet fortios 6.4.14

fortinet fortios 6.4.13

fortinet fortios 6.4.12

fortinet fortios 6.4.11

fortinet fortios 6.4.10

fortinet fortios 6.4.9

fortinet fortios 6.4.8

fortinet fortios 6.4.7

fortinet fortios

fortinet fortiproxy