What Happened
CVE-2024-55591 (CVSS 9.8 — Critical) is an authentication bypass affecting the FortiOS and FortiProxy Node.js WebSocket management interface. Attackers send crafted websocket messages that masquerade as internal requests, bypassing authentication and granting super-administrator access.Observed Exploitation
Arctic Wolf, Fortinet, and multiple incident response firms observed:
- Mass scanning for exposed FortiOS management ports (8443, 443)
- Creation of local admin accounts named
forticloud-techor random 8-character strings - Extraction of firewall configurations, credentials, and routing tables
- VPN policy modification to permit attacker-controlled IPs
- Lateral movement into protected networks within 2-4 hours of initial access
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| FortiOS | 7.0.0–7.0.16 | 7.0.17+ |
| FortiProxy | 7.0.0–7.0.19 | 7.0.20+ |
| FortiProxy | 7.2.0–7.2.12 | 7.2.13+ |
Recommended Actions
- Immediately disable FortiOS management interface access from the internet
- Upgrade to fixed versions listed above
- Review local admin accounts:
get system admin— delete any unfamiliar accounts - Check for config changes since December 2024:
diagnose sys config-history-get - Enable two-factor authentication for all admin accounts