CVE-2024-50568
A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.6
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RL:X/RC:C
- EPSS probability
- 0.41%
- CWE
- CWE-300
- Published
- 2025-06-10
- Last modified
- 2026-03-13
Affected products
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiOS
- Fortinet FortiProxy
- Fortinet FortiProxy
- Fortinet FortiProxy
Weakness type
Related vulnerabilities
- CVE-2026-84197 — In Eclipse Ditto's Node.js JavaScript client, all released versions of...
- CVE-2026-74232 — Zbtlink MQWrt yunmgrd Cloud C2 Implant
- CVE-2026-12991 — Multiple vulnerabilities in Ghost Robotics' Vision 60
- CVE-2025-40770 — A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions)....
- CVE-2025-54792 — LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception
- CVE-2025-20122 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
- CVE-2024-50565 — A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in...
- CVE-2023-38272 — IBM Cloud Pak System information disclosure