CVE-2024-55599: Improper access control in Fortinet FortiOS
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices.
AI Analysis
Technical Summary
This vulnerability involves an improperly implemented security check in Fortinet FortiOS and FortiProxy products that could allow remote unauthenticated attackers to bypass DNS filtering controls specifically when Apple devices are involved. The issue affects multiple major versions of FortiOS and FortiProxy, potentially allowing DNS filter bypass without authentication. The CVSS score of 4.9 indicates a medium severity impact primarily on integrity, with no confidentiality or availability impact. There is no vendor advisory or patch information available at this time, and no known exploits have been reported in the wild.
Potential Impact
The vulnerability allows remote unauthenticated users to bypass DNS filtering protections on affected FortiOS and FortiProxy versions when Apple devices are used. This could lead to users circumventing DNS-based security controls, potentially enabling access to restricted or malicious domains. The impact is limited to integrity as per the CVSS vector, with no direct confidentiality or availability impact reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or remediation level is provided, organizations should monitor Fortinet advisories for updates. In the meantime, consider additional DNS filtering controls or network monitoring to detect potential bypass attempts involving Apple devices.
CVE-2024-55599: Improper access control in Fortinet FortiOS
Description
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices.
CVSS v3.1
Score 4.9medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves an improperly implemented security check in Fortinet FortiOS and FortiProxy products that could allow remote unauthenticated attackers to bypass DNS filtering controls specifically when Apple devices are involved. The issue affects multiple major versions of FortiOS and FortiProxy, potentially allowing DNS filter bypass without authentication. The CVSS score of 4.9 indicates a medium severity impact primarily on integrity, with no confidentiality or availability impact. There is no vendor advisory or patch information available at this time, and no known exploits have been reported in the wild.
Potential Impact
The vulnerability allows remote unauthenticated users to bypass DNS filtering protections on affected FortiOS and FortiProxy versions when Apple devices are used. This could lead to users circumventing DNS-based security controls, potentially enabling access to restricted or malicious domains. The impact is limited to integrity as per the CVSS vector, with no direct confidentiality or availability impact reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or remediation level is provided, organizations should monitor Fortinet advisories for updates. In the meantime, consider additional DNS filtering controls or network monitoring to detect potential bypass attempts involving Apple devices.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- fortinet
- Date Reserved
- 2024-12-09T11:19:49.472Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a27e6ae8dd33fbd8514ca55
Added to database: 06/09/2026, 10:10:54 UTC
Last enriched: 07/15/2026, 11:28:11 UTC
Last updated: 07/25/2026, 08:51:58 UTC
Views: 63
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.