Fortinet warns of auth bypass zero-day exploited to hijack firewalls
ID: 3d4f0719-071b-5f5e-b0e9-18d82d2d6b9a
STIX ID: report--3d4f0719-071b-5f5e-b0e9-18d82d2d6b9a
Feed Name: Bleeping Computer
Fortinet FortiOS and FortiProxy are being actively exploited via a newly disclosed authentication-bypass zero-day (CVE-2024-55591) that grants super-admin privileges through the Node.js websocket interface; attackers have reportedly created random admin/local users, added them to SSL VPN groups, changed firewall policies, and used those accounts to tunnel into internal networks. Arctic Wolf and Fortinet published matching IOCs and a timeline (mid-November to December) and recommend immediately disabling or restricting HTTP/HTTPS administrative access while applying vendor guidance and patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
