---
cve: "CVE-2024-50568"
severity: "MEDIUM"
cvss: 5.6
epss: "37%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2025-06-10 17:19:25"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T13:01:33+02:00"
---

# CVE-2024-50568

> 5.6 MEDIUM

## Beschreibung

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:P/RL:X/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-300** — Channel Accessible by Non-Endpoint
  The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.

## Angriffsmuster (CAPEC)

- [CAPEC-57 — Utilizing REST's Trust in the System Resource to Obtain Sensitive Data](https://capec.mitre.org/data/definitions/57.html) _(Severity: Very High)_
- [CAPEC-466 — Leveraging Active Adversary in the Middle Attacks to Bypass Same Origin Policy](https://capec.mitre.org/data/definitions/466.html) _(Severity: Medium)_
- [CAPEC-589 — DNS Blocking](https://capec.mitre.org/data/definitions/589.html)
- [CAPEC-590 — IP Address Blocking](https://capec.mitre.org/data/definitions/590.html) _(Severity: High)_
- [CAPEC-612 — WiFi MAC Address Tracking](https://capec.mitre.org/data/definitions/612.html) _(Severity: Low)_
- [CAPEC-613 — WiFi SSID Tracking](https://capec.mitre.org/data/definitions/613.html) _(Severity: Low)_
- [CAPEC-615 — Evil Twin Wi-Fi Attack](https://capec.mitre.org/data/definitions/615.html) _(Severity: Low)_
- [CAPEC-662 — Adversary in the Browser (AiTB)](https://capec.mitre.org/data/definitions/662.html) _(Severity: Very High)_

## ATT&CK-Techniken

- [T1040 — Network Sniffing](https://attack.mitre.org/techniques/T1040/)
- [T1185 — Man in the Browser](https://attack.mitre.org/techniques/T1185/)

## Referenzen

- <https://fortiguard.fortinet.com/psirt/FG-IR-24-058>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-50568) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
