Record summary

CVE-2024-50571 has a selected CVSS score of 6.5 (medium).

Description

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 all versions, FortiAnalyzer 6.2 all versions, FortiAnalyzer 6.0 all versions, FortiAnalyzer Cloud 7.4.1 through 7.4.5, FortiAnalyzer Cloud 7.2.1 through 7.2.9, FortiAnalyzer Cloud 7.0.1 through 7.0.13, FortiAnalyzer Cloud 6.4 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager 7.2.0 through 7.2.9, FortiManager 7.0.0 through 7.0.13, FortiManager 6.4 all versions, FortiManager 6.2 all versions, FortiManager 6.0 all versions, FortiManager Cloud 7.6.2, FortiManager Cloud 7.4.1 through 7.4.5, FortiManager Cloud 7.2.1 through 7.2.9, FortiManager Cloud 7.0.1 through 7.0.13, FortiManager Cloud 6.4 all versions, FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiOS 6.2 all versions, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiProxy 7.2.0 through 7.2.12, FortiProxy 7.0.0 through 7.0.19, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1 all versions, FortiProxy 1.0 all versions allows attacker to execute unauthorized code or commands via specifically crafted requests.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2025 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List7.6.0 to ≤ 7.6.2affected
7.4.0 to ≤ 7.4.5affected
7.2.0 to ≤ 7.2.9affected
7.0.0 to ≤ 7.0.13affected
6.4.0 to ≤ 6.4.15affected
6.2.0 to ≤ 6.2.13affected
6.0.0 to ≤ 6.0.12affected

Default status: unaffected

CVE List7.4.1 to ≤ 7.4.5affected
7.2.1 to ≤ 7.2.9affected
7.0.1 to ≤ 7.0.13affected
6.4.1 to ≤ 6.4.7affected

Default status: unaffected

CVE List7.6.0 to ≤ 7.6.1affected
7.4.0 to ≤ 7.4.5affected
7.2.0 to ≤ 7.2.9affected
7.0.0 to ≤ 7.0.13affected
6.4.0 to ≤ 6.4.15affected
6.2.0 to ≤ 6.2.13affected
6.0.0 to ≤ 6.0.12affected

Default status: unaffected

CVE List7.6.2affected
7.4.1 to ≤ 7.4.5affected
7.2.1 to ≤ 7.2.9affected
7.0.1 to ≤ 7.0.13affected
6.4.1 to ≤ 6.4.7affected

Default status: unaffected

CVE List7.6.0affected
7.4.0 to ≤ 7.4.5affected
7.2.0 to ≤ 7.2.10affected
7.0.0 to ≤ 7.0.16affected
6.4.0 to ≤ 6.4.15affected

Default status: unaffected

CVE List7.6.0affected
7.4.0 to ≤ 7.4.6affected
7.2.0 to ≤ 7.2.12affected
7.0.0 to ≤ 7.0.19affected
2.0.0 to ≤ 2.0.14affected
1.2.0 to ≤ 1.2.13affected
1.1.0 to ≤ 1.1.6affected
1.0.0 to ≤ 1.0.7affected

References

2