PT-2025-1051 · Fortinet · Fortios+1

Published

2025-01-14

·

Updated

2026-06-24

·

CVE-2024-55591

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiOS versions 7.0.0 through 7.0.16 FortiProxy versions 7.0.0 through 7.0.19 FortiProxy versions 7.2.0 through 7.2.12
Description An authentication bypass issue exists in the Node.js websocket module of FortiOS and FortiProxy, where an attacker can use an alternate path or channel to circumvent security checks. By sending specially crafted HTTP requests to the Node.js websocket module or crafted CSF proxy requests, a remote attacker can escalate privileges to the super-admin level. This flaw has been exploited in real-world incidents by ransomware groups, including The Gentlemen and NightSpire, and was used in an attack against a manufacturing company to modify firewall policies, VPN settings, and API integrations before deploying RansomHub ransomware.
Recommendations For FortiOS versions 7.0.0 through 7.0.16, update to a version later than 7.0.16. For FortiProxy versions 7.0.0 through 7.0.19, update to a version later than 7.0.19. For FortiProxy versions 7.2.0 through 7.2.12, update to a version later than 7.2.12. As a temporary mitigation, restrict access to the Node.js websocket module and the CSF proxy to minimize the risk of exploitation.

Exploit

Fix

RCE

LPE

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00281
CVE-2024-55591
FORTINET_CVE2024_55591

Affected Products

Fortios
Fortiproxy