CyberICT

CVE-2024-55591

Fortinet · Published January 14, 2025

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Fortinet FortiOS and FortiProxy authentication bypass via crafted Node.js WebSocket module messages allowing an attacker to gain super-admin privileges. Massively exploited in the wild creating rogue admin accounts.

Affected Products

  • FortiOS 7.0.0-7.0.16
  • FortiProxy 7.0.0-7.0.19
  • FortiProxy 7.2.0-7.2.12

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Related Advisories