LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-55591: Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 14, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jan 21, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-55591 to its Known Exploited Vulnerabilities catalog on Jan 14, 2025, with a federal patch deadline of Jan 21, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js…

CVE-2024-55591 is an authentication bypass vulnerability in Fortinet FortiOS and FortiProxy. It can let an unauthenticated remote attacker gain super-admin privileges by sending crafted requests to the Node.js websocket module. Because successful abuse yields full administrative control of the device, the issue is high-impact for any organization that relies on these products for network security or proxy services. CISA notes that the vulnerability has been used by ransomware operators, so rapid identification and remediation are essential.

Defenders should treat any internet-facing or management-exposed FortiOS or FortiProxy instance as potentially at risk until the vendor advisory has been reviewed and the recommended updates or mitigations applied.

How it works

The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). In this case the alternate path is the Node.js websocket module. An attacker who can reach that interface may craft requests that skip normal authentication checks and obtain super-admin rights. Once those privileges are obtained, the attacker can reconfigure the device, create new accounts, alter policies, or pivot deeper into the network. Exact request formats and conditions are not detailed here; they must be confirmed against the vendor advisory. The core risk is that no valid credentials are required if the vulnerable path is reachable.

Am I affected? How to find it in your systems

FortiOS typically runs on Fortinet firewalls, gateways, and related appliances; FortiProxy is used for secure web-proxy and content-filtering deployments. Both products are commonly placed at network perimeters or in DMZs, so management interfaces or websocket endpoints may be reachable from untrusted networks.

Any device whose version falls within the affected range, or whose exposure status cannot be confirmed, should be treated as vulnerable until proven otherwise.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2024-55591. Follow the exact upgrade path and release notes provided by Fortinet; do not rely on version numbers or patch identifiers that are not listed in the official advisory.

Document the remediation steps and retain evidence of the applied update for audit and incident-response purposes.

If you can't patch immediately

When an immediate upgrade is not feasible, reduce exposure with compensating controls while planning the permanent fix.

These measures lower risk but do not eliminate it; schedule the official patch as soon as operationally possible.

If your data may have been exposed

Because this vulnerability has been exploited by ransomware groups, any successful compromise can lead to data theft, encryption, or further network intrusion. If logs or other indicators suggest the device was accessed by an unauthenticated attacker, treat the incident as a potential breach: isolate the device, preserve forensic evidence, and follow your incident-response plan. Organizations can also run a free exposure scan of their email addresses against known breach data sets to determine whether credentials or other information associated with their domain have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiOS and FortiProxy
WeaknessCWE-288
Added to CISA KEVJan 14, 2025
Federal patch deadlineJan 21, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities