CVE-2024-50565: Fortinet Fortianalyzer
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and 6.2.0 through 6.2.13, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and 6.2.0 through 6.2.13, Fortinet FortiVoice version 7.0.0 through 7.0.2, 6.4.0 through 6.4.8 and 6.0.0 through 6.0.12 and Fortinet FortiWeb version 7.4.0 through 7.4.2, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10 allows an unauthenticated attacker in a man-in-the-middle position to impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager), via intercepting the FGFM authentication request between the management device and the managed device
Affected products
- Fortinet Fortianalyzer: from 6.2.0, before 6.2.14 (fixed in 6.2.14); from 6.4.0, before 6.4.15 (fixed in 6.4.15); from 7.0.0, before 7.0.12 (fixed in 7.0.12); from 7.2.0, before 7.2.5 (fixed in 7.2.5); from 7.4.0, before 7.4.3 (fixed in 7.4.3)
- Fortinet FortiManager: from 6.2.0, before 6.2.14 (fixed in 6.2.14); from 6.4.0, before 6.4.15 (fixed in 6.4.15); from 7.0.0, before 7.0.12 (fixed in 7.0.12); from 7.2.0, before 7.2.5 (fixed in 7.2.5); from 7.4.0, before 7.4.3 (fixed in 7.4.3)
- Fortinet FortiOS: from 6.4.0, before 7.0.16 (fixed in 7.0.16); from 7.2.0, before 7.2.9 (fixed in 7.2.9); from 7.4.0, before 7.4.5 (fixed in 7.4.5)
- Fortinet FortiProxy: from 2.0.0, before 7.0.16 (fixed in 7.0.16); from 7.2.0, before 7.2.10 (fixed in 7.2.10); from 7.4.0, before 7.4.3 (fixed in 7.4.3)
- Fortinet Fortivoice: from 6.0.0, before 6.4.9 (fixed in 6.4.9); from 7.0.0, before 7.0.3 (fixed in 7.0.3)
- Fortinet FortiWeb: from 7.4.0, before 7.4.3 (fixed in 7.4.3)
Published 2025-04-08. Last modified 2026-06-17.