An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
The vulnerability results from the ability to bypass the authentication mechanism through an alternative path or communication channel (CWE-288). The attacker sends specially crafted requests to the Node.js websocket module embedded in the device, which allows bypassing standard identity verification. As a result, the attacker gains access with super-admin privilege level without needing to provide any credentials.
A remote attacker, without any authentication, can obtain full super-administrator privileges on the device, enabling complete takeover of the firewall or proxy, modification of network configuration, and potential lateral movement within the protected infrastructure.
FortiOS should be updated as soon as possible to version 7.0.16 or higher, and FortiProxy to version 7.0.19 or higher (7.0.x branch) or 7.2.12 or higher (7.2.x branch). Detailed information on available patches is available in the vendor's security bulletin: https://fortiguard.fortinet.com/psirt/FG-IR-24-535
FortiOS in versions 7.0.0 – 7.0.16 and FortiProxy in versions 7.0.0 – 7.0.19 and 7.2.0 – 7.2.12
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HFortinet FortiOS
OSFortinet7.0.0 – 7.0.17 (excl.)Fortinet Fortiproxy
APPFortinet7.0.0 – 7.0.20 (excl.)7.2.0 – 7.2.13 (excl.)
CISA KEV — detailsi
- Vendori
- Fortinet ↗
- Producti
- FortiOS and FortiProxy
- Added to KEVi
- January 14, 2025
- Remediation deadline (US Federal)i
- January 21, 2025(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Related vulnerabilities
Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach
Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML
Krytyczna podatność format string RCE w Fortinet FortiOS, FortiProxy i FortiSwitchManager
Out-of-bounds write w Fortinet FortiOS i FortiProxy — RCE bez uwierzytelnienia
Krytyczny heap buffer overflow w FortiOS/FortiProxy SSL-VPN umożliwiający RCE