CVE-2024-55591: Execute unauthorized code or commands in Fortinet FortiOS
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
AI Analysis
Technical Summary
CVE-2024-55591 is an authentication bypass vulnerability (CWE-288) affecting Fortinet FortiOS and FortiProxy products. It allows remote attackers to bypass authentication mechanisms by exploiting an alternate path or channel via crafted requests targeting the Node.js websocket module. This results in unauthorized super-admin access. The vulnerability impacts FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12. The vendor has released official patches to remediate this issue.
Potential Impact
Successful exploitation grants an unauthenticated remote attacker super-admin privileges on affected FortiOS and FortiProxy devices. This compromises confidentiality, integrity, and availability of the affected systems, potentially allowing full control over the device and its configurations.
Mitigation Recommendations
An official fix is available from Fortinet. Users should apply the vendor-provided patches for FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 immediately to remediate this vulnerability.
CVE-2024-55591: Execute unauthorized code or commands in Fortinet FortiOS
Observed in the wild — via OffSeq Mirage
Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
CVSS v3.1
Score 9.6critical
Affected software
pkg:github/fortinet/fortiospkg:github/fortinet/fortiproxyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-55591 is an authentication bypass vulnerability (CWE-288) affecting Fortinet FortiOS and FortiProxy products. It allows remote attackers to bypass authentication mechanisms by exploiting an alternate path or channel via crafted requests targeting the Node.js websocket module. This results in unauthorized super-admin access. The vulnerability impacts FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12. The vendor has released official patches to remediate this issue.
Potential Impact
Successful exploitation grants an unauthenticated remote attacker super-admin privileges on affected FortiOS and FortiProxy devices. This compromises confidentiality, integrity, and availability of the affected systems, potentially allowing full control over the device and its configurations.
Mitigation Recommendations
An official fix is available from Fortinet. Users should apply the vendor-provided patches for FortiOS versions 7.0.0 through 7.0.16 and FortiProxy versions 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 immediately to remediate this vulnerability.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- fortinet
- Date Reserved
- 2024-12-09T11:19:49.470Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- official-fix
Threat ID: 68f7d9b6247d717aace26c49
Added to database: 10/21/2025, 19:06:30 UTC
Last enriched: 08/05/2026, 13:07:16 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 212
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.