CVE-2024-55591 – Fortinet FortiOS

CVSS 9.8 CRITICAL Zero Day – Immediate Deployment

“Actively exploited authentication bypass flaws can hand attackers super-admin control of vulnerable Fortinet devices.”

Fortinet patches address two authentication bypass vulnerabilities affecting FortiOS and FortiProxy. CVE-2024-55591 has a CVSS score of 9.6, Critical severity, and allows a remote attacker to gain super-admin privileges through crafted requests to the Node.js WebSocket module. CVE-2025-24472 has a CVSS score of 8.1, High severity, and can allow an unauthenticated attacker with required device information to gain super-admin privileges through crafted Security Fabric proxy requests.

Both vulnerabilities have verified real-world exploitation. Successful attacks can give threat actors administrative control over affected network security infrastructure.

Key Details

Affected Product
Fortinet Fortiproxy
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-288
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.