CVE-2024-50568
published 2025-06-10CVE-2024-50568: A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 &…
PriorityP337medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
0.37%
29.6th percentile
A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.2 < 7.2.9 | 7.2.9 |
| fortinet | fortios | 6.4.2 – 6.4.16 | — |
| fortinet | fortios | 7.0.0 – 7.0.14 | — |
| fortinet | fortios | 7.2.0 – 7.2.7 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | fortios | 7.4.0 – 7.4.3 | — |
| fortinet | fortiproxy | — | — |
| fortinet | fortiproxy | >= 7.0.0 < 7.0.17 | 7.0.17 |
| fortinet | fortiproxy | 7.0.0 – 7.0.16 | — |
| fortinet | fortiproxy | >= 7.2.0 < 7.2.10 | 7.2.10 |
| fortinet | fortiproxy | 7.2.0 – 7.2.9 | — |
| fortinet | fortiproxy | >= 7.4.0 < 7.4.4 | 7.4.4 |
| fortinet | fortiproxy | 7.4.0 – 7.4.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Weak authentication in security fabric daemon
vendor_fortinet·2025-06-10·CVSS 5.9
CVE-2024-50568 [MEDIUM] CWE-300 Weak authentication in security fabric daemon
FG-IR-24-058: Weak authentication in security fabric daemon
A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.
CVEs: CVE-2024-50568
CWEs: CWE-300
CVSS: 5.9 (medium)
Affected products: FortiOS, FortiProxy, Fortinet
GHSA
GHSA-q6xx-gv82-hc4m: A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7
ghsa_unreviewed·2025-06-10
CVE-2024-50568 [MEDIUM] CWE-300 GHSA-q6xx-gv82-hc4m: A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7
A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-06-10
Published