Improper Restriction of Communication Channels in Fortinet FortiOS and Related Products
CVE-2024-50565
3LOW
Key Information:
- Vendor
- Fortinet
- Vendor
- CVE Published:
- 8 April 2025
Summary
Fortinet devices, including FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiVoice, and FortiWeb, contain a vulnerability that allows an unauthenticated attacker in a man-in-the-middle position to intercept FGFM authentication requests. This exploitation enables the attacker to impersonate the management device, potentially leading to unauthorized access and control over network configurations. The affected versions span multiple releases, highlighting the urgency for users to assess their deployments and apply improvements to mitigate this risk.
Affected Version(s)
FortiAnalyzer 7.4.0 <= 7.4.2
FortiAnalyzer 7.2.0 <= 7.2.4
FortiAnalyzer 7.0.0 <= 7.0.11
References
CVSS V3.1
Score:
3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved