Improper restriction of communication channel to intended endpoints in FortiOS - CVE-2024-50565

 

Improper restriction of communication channel to intended endpoints in FortiOS - CVE-2024-50565

Published: April 9, 2025


Vulnerability identifier: #VU107250
CSH Severity: High
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-50565
CWE-ID: CWE-923
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to missing certificate name verification for FGFM connection. A remote non-authenticated attacker can intercept the FGFM authentication request between the management device and the managed device and impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager).

Successful exploitation of the vulnerability may allow an attacker to compromise the affected device.


Affected software

FortiOS
FortiProxy
FortiVoice
FortiManager
FortiAnalyzer
FortiWeb

How to mitigate CVE-2024-50565

Install updates from vendor's website.

FortiOS - addressed in versions 6.2.17, 7.0.16, 7.2.9, 7.4.5
FortiProxy - addressed in versions 7.0.16, 7.2.10, 7.4.3
FortiVoice - addressed in versions 6.4.9, 7.0.3
FortiManager - addressed in versions 6.2.14, 6.4.15, 7.0.12, 7.2.5, 7.4.3
FortiAnalyzer - addressed in versions 6.2.14, 6.4.15, 7.0.12, 7.2.5, 7.4.3
FortiWeb - update to 7.4.3

External References

Related Security Bulletins