Vulnerability record · CVE-2024-55591 · published 14 January 2025
CVE-2024-55591: FortiOS and FortiProxy authentication bypass via Node.js websocket
Fortinet · Fortiproxy
FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 contain an authentication bypass (CWE-288) reachable through crafted requests to the Node.js websocket module. A remote, unauthenticated attacker can obtain super-admin privileges, making this a full compromise of the affected appliance. It is listed in CISA KEV with known ransomware campaign use, so it is being exploited in the wild.
Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote super-admin access with a 9.8 CVSS score, KEV listing, ransomware use and near-maximum EPSS makes this an urgent patch-first issue.
What it is
FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 contain an authentication bypass (CWE-288) reachable through crafted requests to the Node.js websocket module. A remote, unauthenticated attacker can obtain super-admin privileges, making this a full compromise of the affected appliance. It is listed in CISA KEV with known ransomware campaign use, so it is being exploited in the wild.
Impact
An attacker gains super-admin privileges on the device, allowing full control of firewall, proxy and VPN configuration and any credentials or traffic handled by it. That level of access can be used to pivot into the protected network and to disable or alter security controls.
Attack surface
The flaw is network-reachable (CVSS AV:N) with no privileges and no user interaction required (PR:N, UI:N), reached by sending crafted requests to the Node.js websocket module. No authentication is needed, so any host that can reach the exposed service can attempt it.
Exploitation
CISA added it to KEV on 2025-01-14 with a 2025-01-21 remediation due date and flags known ransomware campaign use; EPSS is 0.98259 (99.9th percentile), indicating very high likelihood of exploitation. The vendor advisory is tagged Mitigation and Vendor Advisory, so patched or mitigated versions exist.
What to do
- Apply the Fortinet fixes for FortiOS and FortiProxy per FG-IR-24-535, upgrading off the listed vulnerable ranges.
- If immediate patching is not possible, apply the vendor's documented workarounds or discontinue exposure of the affected management interface as CISA directs.
- Restrict access to administrative and websocket interfaces to trusted management networks; do not expose them to the internet.
- Rotate administrative credentials and any secrets stored on affected devices after remediation, since super-admin access may have been obtained.
- Monitor for and investigate signs of prior compromise before assuming the device is clean.
Detection
- Review FortiOS and FortiProxy logs for unexpected administrative logins, new admin accounts, or configuration changes originating from untrusted source IPs.
- Hunt for anomalous or malformed requests to the Node.js websocket service and for management-interface access from external or unexpected networks.
- Correlate device logs with network telemetry for post-exploitation activity such as new VPN users, firewall rule changes, or outbound connections from the appliance.
- Check for indicators published by Fortinet and CISA for this CVE and search historical logs for matching activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-55591 to the Known Exploited Vulnerabilities catalog on 14 January 2025 as "Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 January 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-24-535 | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55591 | US Government Resource |
Track CVE-2024-55591 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-55591), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.