CVE-2024-55591 - Fortinet FortiOS Authorization Bypass Vulnerability
CVE-2024-55591
Fortinet | FortiOS
- Date Added:
- 2025-01-14
- Due Date:
- 2025-01-21
- Vulnerability Name
Fortinet FortiOS Authorization Bypass Vulnerability
- Description
Fortinet FortiOS contains an authorization bypass vulnerability that may allow an unauthenticated remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
- Known To Be Used in Ransomware Campaigns?
Unknown
- Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Additional Notes
- https://fortiguard.fortinet.com/psirt/FG-IR-24-535 ; https://nvd.nist.gov/vuln/detail/CVE-2024-55591
- Related News Articles
Free online web security scanner