CVE-2024-50571

Severity
7.2HIGH
EPSS
0.1%
top 75.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud 7.2.1 through 7.2.9, FortiAnalyzer Cloud 7.0.1 through 7.0.13, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages12 packages

NVDfortinet/fortimanager_cloud6.4.17.0.14+3
CVEListV5fortinet/fortimanager_cloud7.4.17.4.5+4
NVDfortinet/fortianalyzer_cloud6.4.17.0.14+2
CVEListV5fortinet/fortianalyzer_cloud7.4.17.4.5+3
NVDfortinet/fortimanager6.0.07.0.14+3

🔴Vulnerability Details

3
GHSA
GHSA-4gx4-5v9p-8rrm: A heap-based buffer overflow in Fortinet FortiOS 72025-10-14
CVEList
CVE-2024-50571: A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 72025-10-14
GHSA
SAK-50571 Sakai Kernel users created with type roleview can login as a normal user2024-10-15

📋Vendor Advisories

1
Fortinet
Heap Overflow in fgfmsd2025-10-14
CVE-2024-50571 (HIGH CVSS 7.2) | A heap-based buffer overflow vulner | cvebase.io