CVE-2024-50571
Record summary
CVE-2024-50571 has a selected CVSS score of 6.5 (medium).
Description
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud 7.2.1 through 7.2.9, FortiAnalyzer Cloud 7.0.1 through 7.0.13, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager 7.2.0 through 7.2.9, FortiManager 7.0.0 through 7.0.13, FortiManager 6.4 all versions, FortiManager 6.2 all versions, FortiManager 6.0 all versions, FortiManager Cloud 7.6.2, FortiManager Cloud 7.4.1 through 7.4.5, FortiManager Cloud 7.2.1 through 7.2.9, FortiManager Cloud 7.0.1 through 7.0.13, FortiManager Cloud 6.4 all versions, FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiOS 6.2 all versions, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiProxy 7.2.0 through 7.2.12, FortiProxy 7.0.0 through 7.0.19, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions allows attacker to execute unauthorized code or commands via specifically crafted requests.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2025 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
FortiAnalyzerBrowse Fortinet / FortiAnalyzerDefault status: unaffected | CVE List | 7.6.0 to ≤ 7.6.2 | affected |
| 7.4.0 to ≤ 7.4.5 | affected | ||
| 7.2.0 to ≤ 7.2.9 | affected | ||
| 7.0.0 to ≤ 7.0.13 | affected | ||
| 6.4.0 to ≤ 6.4.15 | affected | ||
| 6.2.0 to ≤ 6.2.13 | affected | ||
| 6.0.0 to ≤ 6.0.12 | affected | ||
FortiAnalyzer CloudBrowse Fortinet / FortiAnalyzer CloudDefault status: unaffected | CVE List | 7.4.1 to ≤ 7.4.5 | affected |
| 7.2.1 to ≤ 7.2.9 | affected | ||
| 7.0.1 to ≤ 7.0.13 | affected | ||
| 6.4.1 to ≤ 6.4.7 | affected | ||
FortiManagerBrowse Fortinet / FortiManagerDefault status: unaffected | CVE List | 7.6.0 to ≤ 7.6.1 | affected |
| 7.4.0 to ≤ 7.4.5 | affected | ||
| 7.2.0 to ≤ 7.2.9 | affected | ||
| 7.0.0 to ≤ 7.0.13 | affected | ||
| 6.4.0 to ≤ 6.4.15 | affected | ||
| 6.2.0 to ≤ 6.2.13 | affected | ||
| 6.0.0 to ≤ 6.0.12 | affected | ||
FortiManager CloudBrowse Fortinet / FortiManager CloudDefault status: unaffected | CVE List | 7.6.2 | affected |
| 7.4.1 to ≤ 7.4.5 | affected | ||
| 7.2.1 to ≤ 7.2.9 | affected | ||
| 7.0.1 to ≤ 7.0.13 | affected | ||
| 6.4.1 to ≤ 6.4.7 | affected | ||
FortiOSBrowse Fortinet / FortiOSDefault status: unaffected | CVE List | 7.6.0 | affected |
| 7.4.0 to ≤ 7.4.5 | affected | ||
| 7.2.0 to ≤ 7.2.10 | affected | ||
| 7.0.0 to ≤ 7.0.16 | affected | ||
| 6.4.0 to ≤ 6.4.15 | affected | ||
FortiProxyBrowse Fortinet / FortiProxyDefault status: unaffected | CVE List | 7.6.0 | affected |
| 7.4.0 to ≤ 7.4.6 | affected | ||
| 7.2.0 to ≤ 7.2.12 | affected | ||
| 7.0.0 to ≤ 7.0.19 | affected | ||
| 2.0.0 to ≤ 2.0.14 | affected | ||
| 1.2.0 to ≤ 1.2.13 | affected | ||
| 1.1.0 to ≤ 1.1.6 | affected | ||
| 1.0.0 to ≤ 1.0.7 | affected |