CVE-2024-50565: No certificate name verification for fgfm connection
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and 6.2.0 through 6.2.13, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and 6.2.0 through 6.2.13, Fortinet FortiVoice version 7.0.0 through 7.0.2, 6.4.0 through 6.4.8 and 6.0.0 through 6.0.12 and Fortinet FortiWeb version 7.4.0 through 7.4.2, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10 allows an unauthenticated attacker in a man-in-the-middle position to impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager), via intercepting the FGFM authentication request between the management device and the managed device
Other sources
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS, FortiProxy, FortiManager, FortiAnalyzer, FortiVoice and FortiWeb may allow an unauthenticated attacker in a man-in-the-middle position to impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager), via intercepting the FGFM authentication request between the management device and the managed device
— FortiGuard
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-50565?
CVE-2024-50565 has a severity level that is typically designated as high due to its potential impact on improper communication channel restrictions.
How do I fix CVE-2024-50565?
To fix CVE-2024-50565, users should upgrade to the respective fixed versions of FortiOS, FortiProxy, and FortiManager as specified by Fortinet.
Which Fortinet products are affected by CVE-2024-50565?
CVE-2024-50565 affects FortiOS, FortiProxy, FortiManager, and FortiAnalyzer across multiple versions.
What is the recommended version to update to for CVE-2024-50565?
The recommended versions to update to for CVE-2024-50565 include FortiOS 7.4.3, FortiProxy 7.4.3, and FortiManager 7.4.3.
What happens if I do not address CVE-2024-50565?
If CVE-2024-50565 is not addressed, it could lead to unauthorized access and a compromise of the network communication channels.