CVE-2024-55591 is a critical authentication bypass vulnerability affecting FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12. This flaw allows a remote, unauthenticated attacker to gain super-admin privileges by sending crafted requests to the Node.js websocket module. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, including in known ransomware campaigns like Qilin, and has garnered significant community discussion and media coverage, although no public Metasploit or ExploitDB modules are currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, < 7.0.20CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
>= 7.2.0, < 7.2.13CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.0.17CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.