CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12
Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Weakness: CWE-288
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiOS | Firewall / NGFW | cna-assigner |
| Fortinet | FortiProxy | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported products (2)
- Fortinet · FortiOS
- Fortinet · FortiProxy
Credit
Fortinet is pleased to thank Sonny of watchTowr ( https://watchtowr.com/) for reporting the CSF related vulnerability under responsible disclosure.
Vendor remediation
Upgrade to FortiOS version 7.0.17 or above Upgrade to FortiProxy version 7.2.13 or above Upgrade to FortiProxy version 7.0.20 or above