CVE-2024-50568: Weak authentication in security fabric daemon
A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.
Other sources
A channel accessible by non-endpoint vulnerability [CWE-300] in FortiOS & FortiProxy may allow an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50568?
CVE-2024-50568 is a critical vulnerability that allows unauthenticated attackers to access sensitive channels in affected versions of Fortinet FortiOS and FortiProxy.
How do I fix CVE-2024-50568?
To mitigate CVE-2024-50568, upgrade FortiOS to version 7.4.4 or higher, or 7.2.9 or higher, and FortiProxy to version 7.4.4 or higher, or 7.2.10 or higher.
Which versions are affected by CVE-2024-50568?
CVE-2024-50568 affects FortiOS versions 7.4.0 to 7.4.3, 7.2.0 to 7.2.8 and prior to 7.0.14, and FortiProxy versions 7.4.0 to 7.4.3, 7.2.0 to 7.2.9 and prior to 7.0.16.
Who is vulnerable to CVE-2024-50568?
Organizations using the specified affected versions of Fortinet FortiOS and FortiProxy without applying the recommended updates are vulnerable to CVE-2024-50568.
What type of vulnerability is CVE-2024-50568?
CVE-2024-50568 is classified as a channel accessible by non-endpoint vulnerability, falling under CWE-300.