Junglewise Threat Intelligence

CVE-2024-55591: Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

CVE-2024-55591 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-01-14

Technologies: Fortinet FortiProxy SSL-VPN, Fortinet FortiOS, Fortinet FortiADC, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

An authentication bypass vulnerability in Fortinet FortiOS and FortiProxy allows a remote, unauthenticated attacker to gain super-admin privileges. The flaw exists in the handling of crafted requests to the Node.js websocket module.

Affected products

  • Fortinet FortiOS 7.0.0 through 7.0.16
  • Fortinet FortiProxy 7.0.0 through 7.0.19, 7.2.0 through 7.2.12

Timeline

  • 2025-01-14: disclosed
  • 2025-01-14: advisory
  • 2025-01-14: kev added: Added to CISA KEV catalog
  • 2025-01-14: exploited: Reported as exploited in the wild per CISA KEV entry.

Related threats