cbcvebase.
CVE-2024-50563
published 2025-01-16

CVE-2024-50563: A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1…

PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.57%
43.2th percentile
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brute-force attack.

Affected

17 ranges
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer>= 7.4.1 < 7.4.47.4.4
fortinetfortianalyzer7.4.1 – 7.4.3
fortinetfortianalyzer>= 7.6.0 < 7.6.27.6.2
fortinetfortianalyzer7.6.0 – 7.6.1
fortinetfortianalyzer_cloud>= 7.4.1 < 7.4.47.4.4
fortinetfortianalyzercloud
fortinetfortimanager
fortinetfortimanager>= 7.4.1 < 7.4.47.4.4
fortinetfortimanager7.4.1 – 7.4.3
fortinetfortimanager>= 7.6.0 < 7.6.27.6.2
fortinetfortimanager7.6.0 – 7.6.1
fortinetfortimanager_cloud>= 7.4.1 < 7.4.47.4.4
fortinetfortimanagercloud
fortinetfortinet
fortinetfortios
fortinetfortiproxy

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability resides in the csfd daemon; monitor for brute-force authentication attempts against this daemon on affected Fortinet products (FortiOS, FortiProxy, FortiManager, FortiAnalyzer and their Cloud variants).
  • Detect repeated failed authentication events targeting the csfd daemon, which may indicate an active brute-force attack attempting to execute unauthorized code or commands.
  • ·The advisory covers two distinct CVEs (CVE-2024-48886 and CVE-2024-50563) under the same FG-IR-24-221 advisory; ensure detections and patches are scoped correctly per product and version range for each CVE.
  • ·The weak authentication flaw is classified as CWE-1390 (Weak Authentication) with a critical CVSS score of 9.0, indicating high exploitability; prioritize patching and rate-limiting/lockout controls on the csfd daemon.
  • ·FortiOS and FortiProxy are additionally affected under the related CVE-2024-48886 (same advisory) but are NOT listed as affected products for CVE-2024-50563 per the NVD entry; scope patching accordingly.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.