CVE-2024-55591
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-55591 is a newly disclosed vulnerability affecting FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12. This issue represents an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288). Maliciously crafted requests to the Node.js websocket module can be exploited by remote attackers to gain super-admin privileges, posing a significant risk to vulnerable systems. Successful exploitation may result in unauthorized access, data theft, or system takeover. Organizations using FortiOS or FortiProxy within the specified versions are strongly advised to upgrade to the latest patched releases as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Fortinet FortiProxy
- FortiOS
Affected Vendors
- Fortinet