Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Critical CVSS 9.8 Listed in CISA KEV
Summary
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Fortinet:FortiOS and FortiProxy
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2024-55591 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://fortiguard.fortinet.com/psirt/FG-IR-24-535 reference
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55591 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD