What Happened

CVE-2024-55591 (CVSS 9.8 — Critical) is an authentication bypass affecting the FortiOS and FortiProxy Node.js WebSocket management interface. Attackers send crafted websocket messages that masquerade as internal requests, bypassing authentication and granting super-administrator access.

Observed Exploitation

Arctic Wolf, Fortinet, and multiple incident response firms observed:

  • Mass scanning for exposed FortiOS management ports (8443, 443)
  • Creation of local admin accounts named forticloud-tech or random 8-character strings
  • Extraction of firewall configurations, credentials, and routing tables
  • VPN policy modification to permit attacker-controlled IPs
  • Lateral movement into protected networks within 2-4 hours of initial access

Affected Versions

ProductVulnerableFixed
FortiOS7.0.0–7.0.167.0.17+
FortiProxy7.0.0–7.0.197.0.20+
FortiProxy7.2.0–7.2.127.2.13+

Recommended Actions

  1. Immediately disable FortiOS management interface access from the internet
  2. Upgrade to fixed versions listed above
  3. Review local admin accounts: get system admin — delete any unfamiliar accounts
  4. Check for config changes since December 2024: diagnose sys config-history-get
  5. Enable two-factor authentication for all admin accounts