PT-2025-24710 · Fortinet · Fortiproxy+1
Published
2025-06-10
·
Updated
2025-06-10
·
CVE-2024-50568
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiOS versions 7.0.0 through 7.0.13
Fortinet FortiOS versions 7.2.0 through 7.2.7
Fortinet FortiOS versions 7.4.0 through 7.4.3
Fortinet FortiProxy versions 7.0.0 through 7.0.15
Fortinet FortiProxy versions 7.2.0 through 7.2.9
Fortinet FortiProxy versions 7.4.0 through 7.4.3
Description
A channel accessible by non-endpoint vulnerability in Fortinet products allows an unauthenticated attacker with knowledge of device-specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.
Recommendations
For Fortinet FortiOS versions 7.0.0 through 7.0.13, update to a version after 7.0.13.
For Fortinet FortiOS versions 7.2.0 through 7.2.7, update to a version after 7.2.7.
For Fortinet FortiOS versions 7.4.0 through 7.4.3, update to a version after 7.4.3.
For Fortinet FortiProxy versions 7.0.0 through 7.0.15, update to a version after 7.0.15.
For Fortinet FortiProxy versions 7.2.0 through 7.2.9, update to a version after 7.2.9.
For Fortinet FortiProxy versions 7.4.0 through 7.4.3, update to a version after 7.4.3.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios
Fortiproxy