CVE-2024-50563

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 1390

Summary

CVE-2024-50563 is a newly disclosed vulnerability affecting multiple Fortinet products, including FortiManager Cloud, FortiAnalyzer, and FortiManager. The weakness lies in a weak authentication mechanism, which can be exploited through brute-force attacks. Successful exploitation enables attackers to execute unauthorized code or commands, potentially leading to serious security implications. Affected versions include FortiManager Cloud 7.4.1 through 7.4.3, FortiAnalyzer versions 7.6.0 through 7.6.1, and FortiAnalyzer Cloud versions 7.4.1 through 7.4.3. FortiManager versions 7.6.0 through 7.6.1, and FortiManager Cloud versions 7.4.1 through 7.4.3 are also affected. It is recommended that users upgrade to the latest patched versions to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • FortiManager
  • FortiAnalyzer

Affected Vendors

  • Fortinet