January 14, 2025 · Applied Cybernetics Group
CVE-2024-55591 — Fortinet FortiOS and FortiProxy
known ransomware use
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
- Added to KEV
2025-01-14- Federal due date
2025-01-21- Vendor
- Fortinet
- Product
- FortiOS and FortiProxy
- EPSS
- 99.9th percentile (score 0.983, as of
2026-07-13) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- ATT&CK
- T1021 , T1068 , T1078 , T1555 · signal rollup
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2024-55591
CISA short description
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
NVD description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.