CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-55591

CVSS 9.8v3.1pub. 2025-01-14upd. 2026-08-05

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

🤖 AI Analysis
How it works

The vulnerability results from the ability to bypass the authentication mechanism through an alternative path or communication channel (CWE-288). The attacker sends specially crafted requests to the Node.js websocket module embedded in the device, which allows bypassing standard identity verification. As a result, the attacker gains access with super-admin privilege level without needing to provide any credentials.

Impact

A remote attacker, without any authentication, can obtain full super-administrator privileges on the device, enabling complete takeover of the firewall or proxy, modification of network configuration, and potential lateral movement within the protected infrastructure.

Mitigation & patch

FortiOS should be updated as soon as possible to version 7.0.16 or higher, and FortiProxy to version 7.0.19 or higher (7.0.x branch) or 7.2.12 or higher (7.2.x branch). Detailed information on available patches is available in the vendor's security bulletin: https://fortiguard.fortinet.com/psirt/FG-IR-24-535

Who is affected

FortiOS in versions 7.0.0 – 7.0.16 and FortiProxy in versions 7.0.0 – 7.0.19 and 7.2.0 – 7.2.12

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Fortinet FortiOS

    OS
    Fortinet
    7.0.0 – 7.0.17 (excl.)
  • Fortinet Fortiproxy

    APP
    Fortinet
    7.0.0 – 7.0.20 (excl.)7.2.0 – 7.2.13 (excl.)

CISA KEV — detailsi

Vendori
Fortinet
Producti
FortiOS and FortiProxy
Added to KEVi
January 14, 2025
Remediation deadline (US Federal)i
January 21, 2025(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 21 stycznia 2025
Tags
Auth BypassFirewall
CWE
References

Related vulnerabilities

CVE-2026-24858CRITICAL9.8⚠ KEVPL ✓same product

Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach

CVE-2025-59718CRITICAL9.8⚠ KEVPL ✓same product

Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML

CVE-2024-23113CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność format string RCE w Fortinet FortiOS, FortiProxy i FortiSwitchManager

CVE-2024-21762CRITICAL9.8⚠ KEVPL ✓same product

Out-of-bounds write w Fortinet FortiOS i FortiProxy — RCE bez uwierzytelnienia

CVE-2023-27997CRITICAL9.8⚠ KEVPL ✓same product

Krytyczny heap buffer overflow w FortiOS/FortiProxy SSL-VPN umożliwiający RCE