CVE-2024-50571
Description
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud 7.2.1 through 7.2.9, FortiAnalyzer Cloud 7.0.1 through 7.0.13, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager 7.2.0 through 7.2.9, FortiManager 7.0.0 through 7.0.13, FortiManager 6.4 all versions, FortiManager 6.2 all versions, FortiManager 6.0 all versions, FortiManager Cloud 7.6.2, FortiManager Cloud 7.4.1 through 7.4.5, FortiManager Cloud 7.2.1 through 7.2.9, FortiManager Cloud 7.0.1 through 7.0.13, FortiManager Cloud 6.4 all versions, FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiOS 6.2 all versions, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiProxy 7.2.0 through 7.2.12, FortiProxy 7.0.0 through 7.0.19, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions allows attacker to execute unauthorized code or commands via specifically crafted requests.
CVSS Details
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Threat Intelligence
Weaknesses 1
Affected Products 24
| Vendor | Product | Version | Range |
|---|---|---|---|
| fortinet | fortianalyzer | * | ≥7.0.0 – <7.0.14 |
| fortinet | fortianalyzer | * | ≥7.2.0 – <7.2.10 |
| fortinet | fortianalyzer | * | ≥7.4.0 – <7.4.6 |
| fortinet | fortianalyzer | * | ≥7.6.0 – <7.6.3 |
| fortinet | fortianalyzer_cloud | * | ≥6.4.1 – <7.0.14 |
| fortinet | fortianalyzer_cloud | * | ≥7.2.1 – <7.2.10 |
| fortinet | fortianalyzer_cloud | * | ≥7.4.1 – <7.4.6 |
| fortinet | fortimanager | * | ≥6.0.0 – <7.0.14 |
| fortinet | fortimanager | * | ≥7.2.0 – <7.2.10 |
| fortinet | fortimanager | * | ≥7.4.0 – <7.4.6 |
| fortinet | fortimanager | * | ≥7.6.0 – <7.6.2 |
| fortinet | fortimanager_cloud | * | ≥6.4.1 – <7.0.14 |
| fortinet | fortimanager_cloud | * | ≥7.2.1 – <7.2.10 |
| fortinet | fortimanager_cloud | * | ≥7.4.1 – <7.4.6 |
| fortinet | fortimanager_cloud | 7.6.2 | any |
| fortinet | fortios | * | ≥6.2.0 – <6.4.16 |
| fortinet | fortios | * | ≥7.0.0 – <7.0.17 |
| fortinet | fortios | * | ≥7.2.0 – <7.2.11 |
| fortinet | fortios | * | ≥7.4.0 – <7.4.7 |
| fortinet | fortios | * | ≥7.6.0 – <7.6.3 |
| fortinet | fortiproxy | * | ≥1.0.0 – <7.0.20 |
| fortinet | fortiproxy | * | ≥7.2.0 – <7.2.13 |
| fortinet | fortiproxy | * | ≥7.4.0 – <7.4.8 |
| fortinet | fortiproxy | 7.6.0 | any |
References 1
- fortiguard.fortinet.com https://fortiguard.fortinet.com/psirt/FG-IR-24-442
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.