CVE-2024-50563
published 2025-01-16CVE-2024-50563: A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.57%
43.6th percentile
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brute-force attack.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | >= 7.4.1 < 7.4.4 | 7.4.4 |
| fortinet | fortianalyzer | 7.4.1 – 7.4.3 | — |
| fortinet | fortianalyzer | >= 7.6.0 < 7.6.2 | 7.6.2 |
| fortinet | fortianalyzer | 7.6.0 – 7.6.1 | — |
| fortinet | fortianalyzer_cloud | >= 7.4.1 < 7.4.4 | 7.4.4 |
| fortinet | fortianalyzercloud | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 7.4.1 < 7.4.4 | 7.4.4 |
| fortinet | fortimanager | 7.4.1 – 7.4.3 | — |
| fortinet | fortimanager | >= 7.6.0 < 7.6.2 | 7.6.2 |
| fortinet | fortimanager | 7.6.0 – 7.6.1 | — |
| fortinet | fortimanager_cloud | >= 7.4.1 < 7.4.4 | 7.4.4 |
| fortinet | fortimanagercloud | — | — |
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortiproxy | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability resides in the csfd daemon; monitor for brute-force authentication attempts against this daemon on affected Fortinet products (FortiOS, FortiProxy, FortiManager, FortiAnalyzer and their Cloud variants). ↗
- →Detect repeated failed authentication events targeting the csfd daemon, which may indicate an active brute-force attack attempting to execute unauthorized code or commands. ↗
- ·The advisory covers two distinct CVEs (CVE-2024-48886 and CVE-2024-50563) under the same FG-IR-24-221 advisory; ensure detections and patches are scoped correctly per product and version range for each CVE. ↗
- ·The weak authentication flaw is classified as CWE-1390 (Weak Authentication) with a critical CVSS score of 9.0, indicating high exploitability; prioritize patching and rate-limiting/lockout controls on the csfd daemon. ↗
- ·FortiOS and FortiProxy are additionally affected under the related CVE-2024-48886 (same advisory) but are NOT listed as affected products for CVE-2024-50563 per the NVD entry; scope patching accordingly. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Weak Authentication in csfd daemon
vendor_fortinet·2025-01-14·CVSS 9.0
CVE-2024-48886 [CRITICAL] CWE-1390 Weak Authentication in csfd daemon
FG-IR-24-221: Weak Authentication in csfd daemon
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brute-force attack.
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions
GHSA
GHSA-w3ph-4wxh-3hvv: A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7
ghsa_unreviewed·2025-01-16
CVE-2024-50563 [HIGH] CWE-1390 GHSA-w3ph-4wxh-3hvv: A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to execute unauthorized code or commands via a brute-force attack.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-16
Published