CVE-2024-50565
CVE-2024-50565: An improper restriction of the communication channel vulnerability exists in multiple Fortinet products. This flaw allows an unauthenticated attacker in a man-in-the-middle position to impersonate the management device. Specifically, the attacker can intercept the FGFM authentication request between the management device and the managed device. Affected products include FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiVoice and FortiWeb across various versions. Despite a low CVSS score of 3.1, the SOCRadar Vulnerability Risk Score (SVRS) of 37 indicates a notable level of risk, primarily due to the potential for man-in-the-middle attacks and the wide range of affected Fortinet products. Organizations should review and update their Fortinet installations to the latest patched versions to mitigate the risk of exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.