CVE-2024-55591
Last modified
CVE-2024-55591 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.. CISA has confirmed active exploitation in the wild. EPSS estimates a 98.26% chance of exploitation in the next 30 days.
Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiproxy | >= 7.0.0, < 7.0.20 |
| Fortinet | Fortiproxy | >= 7.2.0, < 7.2.13 |
| Fortinet | Fortios | >= 7.0.0, < 7.0.17 |
References
- https://fortiguard.fortinet.com/psirt/FG-IR-24-535Mitigation, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55591US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-55591?
How severe is CVE-2024-55591?
How do I fix CVE-2024-55591?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-55582Oxide before 6 has unencrypted Control Plane datastores.5.7
- CVE-2024-55585In the moPS App through 1.8.618, all users can access admini…9
- CVE-2024-55586Nette Database through 3.2.4 allows SQL injection in certain…9.8
- CVE-2024-55587python-libarchive through 4.2.1 allows directory traversal (…8.8
- CVE-2024-5559CWE-327: Use of a Broken or Risky Cryptographic Algorithm vu…6.8
- CVE-2024-55590Multiple improper neutralization of special elements used in…8.8
- CVE-2024-55592An incorrect authorization vulnerability [CWE-863] in FortiS…3.8
- CVE-2024-55593A improper neutralization of special elements used in an sql…2.7
- CVE-2024-55594An improper handling of syntactically invalid structure in F…9.8
- CVE-2024-55595Rejected reason: Not used
- CVE-2024-55597A improper limitation of a pathname to a restricted director…7.2
- CVE-2024-55599An Improperly Implemented Security Check for Standard vulner…5.3
Are you affected by CVE-2024-55591?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
