Improper restriction of communication channel to intended endpoints in FortiOS - CVE-2024-50565
Published: April 9, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to missing certificate name verification for FGFM connection. A remote non-authenticated attacker can intercept the FGFM authentication request between the management device and the managed device and impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager).
Successful exploitation of the vulnerability may allow an attacker to compromise the affected device.
Affected software
FortiProxy
FortiVoice
FortiManager
FortiAnalyzer
FortiWeb
How to mitigate CVE-2024-50565
FortiProxy - addressed in versions 7.0.16, 7.2.10, 7.4.3
FortiVoice - addressed in versions 6.4.9, 7.0.3
FortiManager - addressed in versions 6.2.14, 6.4.15, 7.0.12, 7.2.5, 7.4.3
FortiAnalyzer - addressed in versions 6.2.14, 6.4.15, 7.0.12, 7.2.5, 7.4.3
FortiWeb - update to 7.4.3