peter bassill · operator
$ cve CVE-2024-55591 JSON

CVE-2024-55591 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 94.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-01-21.

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS94.15% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-288
On CISA KEVyes — remediate by 2025-01-21
Public exploitnone known
Published2025-01-14
Last modified2026-08-05

CISA KEV

NameFortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Added2025-01-14
Due2025-01-21
Vendor / productFortinet / FortiOS and FortiProxy
Ransomware useknown

Affected (2)

VendorProduct
fortinetfortios
fortinetfortiproxy

References

→ the Explorer  ·  watch your stack  ·  NVD