CVE-2024-55591 – Fortinet FortiOS
“Actively exploited authentication bypass flaws can hand attackers super-admin control of vulnerable Fortinet devices.”
Fortinet patches address two authentication bypass vulnerabilities affecting FortiOS and FortiProxy. CVE-2024-55591 has a CVSS score of 9.6, Critical severity, and allows a remote attacker to gain super-admin privileges through crafted requests to the Node.js WebSocket module. CVE-2025-24472 has a CVSS score of 8.1, High severity, and can allow an unauthenticated attacker with required device information to gain super-admin privileges through crafted Security Fabric proxy requests.
Both vulnerabilities have verified real-world exploitation. Successful attacks can give threat actors administrative control over affected network security infrastructure.
Key Details
- Affected Product
- Fortinet Fortiproxy
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-288