CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
- Affected products
- Fortios, Fortiproxy
- Fortinet Fortiproxy
- < 7.0.20, 7.2.13
- Fortinet Fortios
- < 7.0.17
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 98.3% (100th percentile)
- Weakness
- CWE-288
- NVD status
- Analyzed
- Published
- 2025-01-14
Fix
Upgrade to FortiOS version 7.0.17 or above Upgrade to FortiProxy version 7.2.13 or above Upgrade to FortiProxy version 7.0.20 or above
CVE-2024-55591 at NVD
19 known exploits for CVE-2024-55591
Proof-of-concept code and exploit modules indexed by Sploitus
cve-2024-55591-poc
CVE-2024-55591
CVE-2024-55591-POC
fortios-auth-bypass-poc-CVE-2024-55591
fortios-auth-bypass-exploit-CVE-2024-55591
CVE-2024-55591-POC
Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy
fortios-auth-bypass-poc-CVE-2024-55591
CVE-2024-55591
fortios-auth-bypass-check-CVE-2024-55591
FortiGate-FortiWeb-Multi-Exploit-Extractor
Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy
Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy
Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy
Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy
Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy
Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy
Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy
Exploit for Authentication Bypass Using an Alternate Path or Channel in Fortinet Fortiproxy