CVE-2024-50565

April 8, 2025, 6:13 p.m.

3.1
Low

Description

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and 6.2.0 through 6.2.13, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and 6.2.0 through 6.2.13, Fortinet FortiVoice version 7.0.0 through 7.0.2, 6.4.0 through 6.4.8 and 6.0.0 through 6.0.12 and Fortinet FortiWeb version 7.4.0 through 7.4.2, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10 allows an unauthenticated attacker in a man-in-the-middle position to impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager), via intercepting the FGFM authentication request between the management device and the managed device

Product(s) Impacted

Product Versions
fortios
  • 6.4.0-6.4.15
fortiproxy
  • 7.4.0-7.4.2
fortiproxy
  • 7.2.0-7.2.9
fortimanager
  • 7.4.0-7.4.2
fortimanager
  • 7.2.0-7.2.4
fortimanager
  • 7.0.0-7.0.11
fortimanager
  • 6.4.0-6.4.14
fortianalyzer
  • 7.4.0-7.4.2
fortianalyzer
  • 7.2.0-7.2.4
fortianalyzer
  • 7.0.0-7.0.11
fortianalyzer
  • 6.4.0-6.4.14
fortivoice
  • 7.0.0-7.0.2
fortios
  • 7.4.0-7.4.3
fortios
  • 7.2.0-7.2.7
fortios
  • 7.0.0-7.0.14
fortios
  • 6.2.0-6.2.16
fortiproxy
  • 7.0.0-7.0.15
fortiproxy
  • 2.0.0-2.0.14
fortimanager
  • 6.2.0-6.2.13
fortianalyzer
  • 6.2.0-6.2.13
fortivoice
  • 6.4.0-6.4.8
fortivoice
  • 6.0.0-6.0.12
fortiweb
  • 7.4.0-7.4.2
fortiweb
  • 7.2.0-7.2.10
fortiweb
  • 7.0.0-7.0.10

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-300
Channel Accessible by Non-Endpoint
The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.

CVSS Score

3.1 / 10

CVSS Data - 3.1

  • Attack Vector: NETWORK
  • Attack Complexity: HIGH
  • Privileges Required: NONE
  • Scope: UNCHANGED
  • Confidentiality Impact: NONE
  • Integrity Impact: LOW
  • Availability Impact: NONE
  • CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

    View Vector String

Timeline

Published: April 8, 2025, 2:15 p.m.
Last Modified: April 8, 2025, 6:13 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

psirt@fortinet.com

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.