#FortiSwitch
CVE-2023-37936 (CVSS 9.6): Urgent Patch Needed for FortiSwitch Vulnerability
CVE-2023-37936 (CVSS 9.6): Urgent Patch Needed for FortiSwitch Vulnerability
Critical security vulnerability (CVE-2023-37936) affecting FortiSwitch product line. Learn about the impact, mitigation, and recommended patches.
securityonline.info
January 15, 2025 at 12:24 PM
Fortinet has released security patches for a critical vulnerability in its FortiSwitch devices that can be exploited to change administrator passwords remotely.
Critical FortiSwitch flaw lets hackers change admin passwords remotely
Fortinet has released security patches for a critical vulnerability in its FortiSwitch devices that can be exploited to change administrator passwords remotely.
www.bleepingcomputer.com
April 9, 2025 at 4:09 PM
Fortinet FortiSwitch has an "extremely critical" vulnerability (CVE-2024-48887) with a CVSS score of 9.3. An unauthenticated user could exploit it to change the password for an administrative account, gaining administrative privileges on the device. Fortinet has issued an advisory.
Fortinet FortiSwitch "extremely critical" vulnerability
Fortinet has issued an advisory for its Fortinet FortiSwitch product. An unauthenticated user may be able to exploit a vulnerability in the web administration interface to change the password for a...
reddit.com
April 9, 2025 at 12:42 AM
Oh is it time for another Fortinet crit again? Unauthenticated admin password change in FortiSwitch.

CVE-2024-48887, CVSSv3 9.3

fortiguard.fortinet....

#CVE #ThreatIntel
PSIRT | FortiGuard Labs
None
fortiguard.fortinet.com
April 9, 2025 at 6:33 AM
🌍 #𝗖𝗬𝗕𝗘𝗥𝗩𝗘𝗜𝗟𝗟𝗘 🌍
Fortinet : cette faille critique dans FortiSwitch permet de changer le mot de passe admin à distance
FortiSwitch : une faille permet de changer le mot de passe à distance
Les équipements FortiSwitch sont affectés par une faille de sécurité critique permettant de changer le mot de passe à distance : CVE-2024-48887.
www.it-connect.fr
April 14, 2025 at 11:09 AM
FortiPAM and FortiSwitch Manager Vulnerability Let Attackers Bypass Authentication Process
FortiPAM and FortiSwitch Manager Vulnerability Let Attackers Bypass Authentication Process
Fortinet has issued an urgent advisory revealing a critical weakness in its FortiPAM and FortiSwitch Manager products that could allow attackers to sidestep authentication entirely through brute-force methods. Tracked as CVE-2025-49201, the flaw stems from a weak authentication mechanism in the Web Application Delivery (WAD) and Graphical User Interface (GUI) components, classified under CWE-1390. With a CVSS v3.1 score of 7.4, rated as high severity, the vulnerability poses risks of unauthorized code execution or command injection, potentially granting remote attackers full control over affected systems. The issue affects multiple versions of FortiPAM, Fortinet’s privileged access management solution, and select releases of FortiSwitch Manager, which handles network switch configurations. Specifically, FortiPAM versions 1.5.0, 1.4.0 through 1.4.2, and all versions of 1.3, 1.2, 1.1, and 1.0 are vulnerable. For FortiSwitch Manager, versions 7.2.0 through 7.2.4 in the 7.2 series are impacted, while the 7.0 series remains unaffected. Product Affected Versions Solution FortiPAM 1.7 Not affected Not Applicable FortiPAM 1.6 Not affected Not Applicable FortiPAM 1.5 1.5.0 Upgrade to 1.5.1 or above FortiPAM 1.4 1.4.0 through 1.4.2 Upgrade to 1.4.3 or above FortiPAM 1.3 1.3 all versions Migrate to a fixed release FortiPAM 1.2 1.2 all versions Migrate to a fixed release FortiPAM 1.1 1.1 all versions Migrate to a fixed release FortiPAM 1.0 1.0 all versions Migrate to a fixed release FortiSwitchManager 7.2 7.2.0 through 7.2.4 Upgrade to 7.2.5 or above FortiSwitchManager 7.0 Not affected Not Applicable Attackers require network access and could exploit this over time with persistent brute-force attempts , though no public exploits have surfaced yet. Fortinet urges immediate patching to mitigate threats. Users on vulnerable FortiPAM 1.5 should upgrade to 1.5.1 or later, while those on 1.4 need version 1.4.3 or above. For older branches like 1.3 and below, migration to a fixed release is essential. FortiSwitch Manager 7.2 users must update to 7.2.5 or higher. The company emphasizes monitoring for unusual login attempts and implementing multi-factor authentication as interim defenses. Discovered internally by Gwendal Guégniaud from Fortinet’s Product Security team, the vulnerability was published on October 14, 2025, under internal reference FG-IR-25-010. This disclosure comes amid rising concerns over supply chain attacks targeting network management tools, underscoring the need for swift updates in enterprise environments. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post FortiPAM and FortiSwitch Manager Vulnerability Let Attackers Bypass Authentication Process appeared first on Cyber Security News .
cybersecuritynews.com
October 14, 2025 at 7:36 PM
Critical alert for Fortinet users! A 9.3 CVSS flaw (CVE-2024-48887) in FortiSwitch lets hackers remotely change admin passwords — no login needed.

🔧 Fix it: Upgrade ASAP (7.6.1+, 7.4.5+, 7.2.9+, 7.0.11+, 6.4.15+)

⚡ No exploits yet—but Fortinet bugs have been weaponized before.
#CyberSecurity
Fortinet Urges FortiSwitch Upgrades to Patch Critical Admin Password Change Flaw
Fortinet patches CVE-2024-48887, a 9.3 CVSS FortiSwitch flaw, urging quick upgrades to avoid attacks.
thehackernews.com
April 9, 2025 at 1:37 AM
Der Anbieter von IT-Securitylösungen Fortinet hat zahlreiche Sicherheitsupdates für seine Produkte veröffentlicht. Das sollten Netzwerkadmins im Blick haben. #Security
Patchday Fortinet: Hintertür ermöglicht unbefugte Zugriffe auf FortiSwitch
Der Anbieter von IT-Securitylösungen Fortinet hat zahlreiche Sicherheitsupdates für seine Produkte veröffentlicht. Das sollten Netzwerkadmins im Blick haben.
www.heise.de
January 15, 2025 at 2:14 PM
Kritieke kwetsbaarheid FortiSwitch maakte veranderen adminwachtwoorden mogelijk
Kritieke kwetsbaarheid FortiSwitch maakte veranderen adminwachtwoorden mogelijk
tweakers.net
April 8, 2025 at 7:22 PM
Fortinet Patches Critical FortiSwitch Vulnerability
Fortinet Patches Critical FortiSwitch Vulnerability
Fortinet fixes a critical-severity bug in FortiSwitch that could allow an attacker to modify administrative passwords.
buff.ly
April 11, 2025 at 11:12 PM
Fortinet FortiSwitch-148F-POE Switch II price incl VAT 3 yr warranty* B2B
Refurb · 952.87 · eBay #homelab #selfhosted
Fortinet FortiSwitch-148F-POE Switch II price incl VAT 3 yr warranty* B2B
Refurb · 952.87 — track it on DealKestrel
www.ebay.com
July 18, 2026 at 10:45 AM
Fortinet FortiSwitch-448E-POE Switch II price incl VAT 3 yr warranty* B2B
Refurb · 2363.75 · eBay #homelab #selfhosted
Fortinet FortiSwitch-448E-POE Switch II price incl VAT 3 yr warranty* B2B
Refurb · 2363.75 — track it on DealKestrel
www.ebay.com
August 15, 2026 at 2:45 PM
Fortinet Warns of FortiSwitch Vulnerability Let Attackers Modify Admin Passwords
Fortinet Warns of FortiSwitch Vulnerability Let Attackers Modify Admin Passwords
cybersecuritynews.com
April 8, 2025 at 3:03 PM
Notícia da SecurityOnline

"CVE-2023-37936 (CVSS 9.6): Patch Urgente Necessário para Vulnerabilidade do FortiSwitch" #bolhasec
CVE-2023-37936 (CVSS 9.6): Urgent Patch Needed for FortiSwitch Vulnerability
Critical security vulnerability (CVE-2023-37936) affecting FortiSwitch product line. Learn about the impact, mitigation, and recommended patches.
securityonline.info
January 23, 2025 at 2:30 AM
Fortinet Urges FortiSwitch Upgrades to Patch Critical Admin Password Change Flaw
Fortinet Urges FortiSwitch Upgrades to Patch Critical Admin Password Change Flaw
thehackernews.com
April 8, 2025 at 6:54 PM
🚨 CVE-2024-48887 — Critical FortiSwitch flaw (CVSS 9.3) 
 
Affected: 6.4.0–7.6.0 
Patch ASAP or disable HTTP/HTTPS admin access. 
Find exposed assets with Modat Magnify: 
cert~"FortiSwitch" 
 
magnify.modat.io 
 
#CVE-2024-48887 #Fortinet #FortiSwitch #Cybersecurity #Infosec #Vulnerability #PatchNow
April 9, 2025 at 2:13 PM
🚨🚨CVE-2023-37936 (CVSS 9.6): Urgent Patch Needed for FortiSwitch Vulnerability

securityonline.info/cve-2023-379...
CVE-2023-37936 (CVSS 9.6): Urgent Patch Needed for FortiSwitch Vulnerability
Critical security vulnerability (CVE-2023-37936) affecting FortiSwitch product line. Learn about the impact, mitigation, and recommended patches.
securityonline.info
January 15, 2025 at 12:34 PM
Critical FortiSwitch vulnerability (CVE-2024-48887) lets attackers remotely change admin passwords (versions 6.4.0-7.6.0). Patches (6.4.15, 7.0.11, 7.2.9, 7.4.5, 7.6.1) and a workaround are available. Severity: 9.8/10.#FortiSwitchCVE202448887
April 9, 2025 at 10:07 PM
Fortinet Urges FortiSwitch Upgrades to Patch Critical Admin Password Change Flaw thehackernews.com/2025/04/fort...
Fortinet Urges FortiSwitch Upgrades to Patch Critical Admin Password Change Flaw
Fortinet patches CVE-2024-48887, a 9.3 CVSS FortiSwitch flaw, urging quick upgrades to avoid attacks.
thehackernews.com
April 8, 2025 at 10:37 PM
🔧 Dealing with high memory usage on your FortiSwitch? Our guide provides solutions to diagnose and resolve memory consumption issues. 🖥️⚙️ Learn more here: pupuweb.com/how-to-fix-f... #FortiSwitch #TechSupport #NetworkManagement
How to fix FortiSwitch high memory usage - PUPUWEB
This article describes how high memory usage on a FortiSwitch could be triggered due to a few reasons and how to analyze high memory usage on a
pupuweb.com
August 1, 2024 at 3:19 PM
Tracked as CVE-2024-48887 (CVSS score of 9.3), the FortiSwitch issue could allow an attacker to modify administrative passwords, the company warns. www.securityweek.com/fortinet-pat...
Fortinet Patches Critical FortiSwitch Vulnerability
Fortinet fixes a critical-severity bug in FortiSwitch that could allow an attacker to modify administrative passwords.
www.securityweek.com
April 9, 2025 at 12:59 PM
Fortinet aktualisiert unter anderem FortiOS, FortiPAM und FortiSwitch Manager | Security www.heise.de/news/Fortine...
Fortinet aktualisiert unter anderem FortiOS, FortiPAM und FortiSwitch Manager
Patchday auch bei Fortinet: Der Hersteller hat mehrere Lücken geschlossen, die für Bösewichte als Bestandteil einer Angriffs-Kill-Chain attraktiv sein könnten.
www.heise.de
October 15, 2025 at 8:20 PM
前職で最後に担当した製品のリリースがようやく決まったみたいです
まあ、色々思うところはあるのですが、ラージエンプラのコアスイッチとして使う分には何の問題もない製品仕様になっていると自負していますので、可愛がっていただけるとありがたいです
cloud.watch.impress.co.jp/docs/news/20...
フォーティネット、初のシャーシ型スイッチ「FortiSwitch-AX9000G」を国内先行販売
フォーティネットジャパン合同会社(以下、フォーティネット)は13日、シャーシ型スイッチ製品「FortiSwitch-AX9000Gシリーズ」を、…グローバル展開に先立ち、日本市場での先行販売を開始すると発表した。
cloud.watch.impress.co.jp
November 14, 2025 at 3:44 AM