#VU107250 Improper restriction of communication channel to intended endpoints in FortiOS - CVE-2024-50565
Published: April 9, 2025
FortiOS
Fortinet, Inc
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to missing certificate name verification for FGFM connection. A remote non-authenticated attacker can intercept the FGFM authentication request between the management device and the managed device and impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager).
Successful exploitation of the vulnerability may allow an attacker to compromise the affected device.