Improper Restriction of Communication Channels in Fortinet FortiOS and Related Products
CVE-2024-50565
3LOW
Key Information:
- Vendor
Fortinet
- Vendor
- CVE Published:
- 8 April 2025
What is CVE-2024-50565?
Fortinet devices, including FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiVoice, and FortiWeb, contain a vulnerability that allows an unauthenticated attacker in a man-in-the-middle position to intercept FGFM authentication requests. This exploitation enables the attacker to impersonate the management device, potentially leading to unauthorized access and control over network configurations. The affected versions span multiple releases, highlighting the urgency for users to assess their deployments and apply improvements to mitigate this risk.
Affected Version(s)
FortiAnalyzer 7.4.0 <= 7.4.2
FortiAnalyzer 7.2.0 <= 7.2.4
FortiAnalyzer 7.0.0 <= 7.0.11