CVE-2024-55591
Fortinet · Published January 14, 2025
9.8
CVSS v3.1
CRITICALCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Fortinet FortiOS and FortiProxy authentication bypass via crafted Node.js WebSocket module messages allowing an attacker to gain super-admin privileges. Massively exploited in the wild creating rogue admin accounts.
Affected Products
- FortiOS 7.0.0-7.0.16
- FortiProxy 7.0.0-7.0.19
- FortiProxy 7.2.0-7.2.12
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H