logo

CVE-2024-55591: Fortinet Authentication Bypass Zero-Day Vulnerability Exploited in the Wild

ID: 4a7b4f3f-6ed8-5c0b-a1ce-e696f6c5440b

STIX ID: report--4a7b4f3f-6ed8-5c0b-a1ce-e696f6c5440b

Feed Name: Tenable Blog

Threat Score
90/100

Date Published: 2025-01-14

Date Updated: 2026-05-01

Author: Scott Caveza

...
...

Tenable reports that Fortinet patched a critical authentication bypass zero-day in FortiOS and FortiProxy (CVE-2024-55591, later supplemented by CVE-2025-24472) which has been actively exploited in the wild since at least November 2024; successful exploitation can grant super-admin privileges. The advisory describes attack vectors (crafted Node.js websocket or CSF proxy requests), overlaps with an Arctic Wolf-observed campaign (scanning, reconnaissance, SSL VPN configuration, lateral movement), affected product versions, available patches and workarounds, and included IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.