cbcvebase.
CVE-2024-50563
published 2025-01-16

CVE-2024-50563: A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brute-force attack.

Affected

17 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer>= 7.4.1 < 7.4.47.4.4
fortinetfortianalyzer7.4.1 – 7.4.3
fortinetfortianalyzer>= 7.6.0 < 7.6.27.6.2
fortinetfortianalyzer7.6.0 – 7.6.1
fortinetfortianalyzer_cloud>= 7.4.1 < 7.4.47.4.4
fortinetfortianalyzercloud
fortinetfortimanager
fortinetfortimanager>= 7.4.1 < 7.4.47.4.4
fortinetfortimanager7.4.1 – 7.4.3
fortinetfortimanager>= 7.6.0 < 7.6.27.6.2
fortinetfortimanager7.6.0 – 7.6.1
fortinetfortimanager_cloud>= 7.4.1 < 7.4.47.4.4
fortinetfortimanagercloud
fortinetfortinet
fortinetfortios
fortinetfortiproxy