{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-50566","assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","state":"PUBLISHED","assignerShortName":"fortinet","dateReserved":"2024-10-24T11:52:14.401Z","datePublished":"2025-01-14T14:08:35.384Z","dateUpdated":"2026-01-15T15:05:48.819Z"},"containers":{"cna":{"affected":[{"vendor":"Fortinet","product":"FortiManager","cpes":["cpe:2.3:o:fortinet:fortimanager:7.6.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.6.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.1:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.4.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.8:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.7:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.6:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.5:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.4:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.3:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.2:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:fortimanager:7.2.1:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"versionType":"semver","version":"7.6.0","lessThanOrEqual":"7.6.1","status":"affected"},{"versionType":"semver","version":"7.4.0","lessThanOrEqual":"7.4.5","status":"affected"},{"versionType":"semver","version":"7.2.1","lessThanOrEqual":"7.2.8","status":"affected"}]},{"vendor":"Fortinet","product":"FortiManager Cloud","cpes":["cpe:2.3:a:fortinet:fortimanagercloud:7.4.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimanagercloud:7.4.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimanagercloud:7.4.2:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimanagercloud:7.4.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimanagercloud:7.2.7:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimanagercloud:7.2.6:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimanagercloud:7.2.5:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimanagercloud:7.2.4:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimanagercloud:7.2.3:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortimanagercloud:7.2.2:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"versionType":"semver","version":"7.4.1","lessThanOrEqual":"7.4.4","status":"affected"},{"versionType":"semver","version":"7.2.2","lessThanOrEqual":"7.2.7","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through 7.4.5, FortiManager 7.2.1 through 7.2.8 may allow an authenticated remote attacker to execute unauthorized code via FGFM crafted requests."}],"providerMetadata":{"orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet","dateUpdated":"2026-01-15T15:05:48.819Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-78","description":"Execute unauthorized code or commands","type":"CWE"}]}],"metrics":[{"format":"CVSS","cvssV3_1":{"version":"3.1","attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:H/RL:U/RC:X"}}],"solutions":[{"lang":"en","value":"Upgrade to FortiManager version 7.6.2 or above\nUpgrade to FortiManager version 7.4.6 or above\nUpgrade to FortiManager version 7.2.9 or above\nUpgrade to FortiManager Cloud version 7.6.2 or above\nUpgrade to FortiManager Cloud version 7.4.5 or above\nUpgrade to FortiManager Cloud version 7.2.8 or above"}],"references":[{"name":"https://fortiguard.fortinet.com/psirt/FG-IR-24-463","url":"https://fortiguard.fortinet.com/psirt/FG-IR-24-463"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-01-14T15:16:49.654273Z","id":"CVE-2024-50566","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-01-14T20:57:06.777Z"}}]}}