Heap-based buffer overflow in Fortinet, Inc products - CVE-2024-50571
Published: October 14, 2025
Vulnerability identifier: #VU117134
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-50571
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in fgfmsd. An authenticated attacker can execute arbitrary code or commands via specifically crafted requests.
Affected software
FortiProxy
FortiAnalyzer
FortiManager
FortiOS
FortiAnalyzer Cloud
FortiAnalyzer
FortiManager
FortiOS
FortiAnalyzer Cloud
How to mitigate CVE-2024-50571
Install update from vendor's website.
FortiProxy - addressed in versions 7.0.20, 7.2.13, 7.4.8, 7.6.2
FortiAnalyzer - addressed in versions 7.0.14, 7.2.10, 7.4.6, 7.6.3
FortiManager - addressed in versions 7.0.14, 7.2.10, 7.4.6, 7.6.2
FortiOS - addressed in versions 6.4.16, 7.0.17, 7.2.11, 7.4.7, 7.6.3
FortiAnalyzer Cloud - addressed in versions 7.0.14, 7.2.10, 7.4.6
FortiAnalyzer - addressed in versions 7.0.14, 7.2.10, 7.4.6, 7.6.3
FortiManager - addressed in versions 7.0.14, 7.2.10, 7.4.6, 7.6.2
FortiOS - addressed in versions 6.4.16, 7.0.17, 7.2.11, 7.4.7, 7.6.3
FortiAnalyzer Cloud - addressed in versions 7.0.14, 7.2.10, 7.4.6