Fortinet discloses second firewall auth bypass patched in January
ID: b8bec6f8-4bf7-5f64-b79e-d9c9bf5d22ce
STIX ID: report--b8bec6f8-4bf7-5f64-b79e-d9c9bf5d22ce
Feed Name: Bleeping Computer
Fortinet warned of actively exploited authentication-bypass vulnerabilities in FortiOS and FortiProxy (CVE-2024-55591 and CVE-2025-24472) that allowed remote attackers to gain super-admin privileges by crafting CSF proxy or Node.js websocket requests; attackers created admin accounts, altered firewall policies, and used SSL VPN to move laterally. Arctic Wolf provided matching IOCs and a multi-phase exploitation timeline, and Fortinet issued patches and workarounds, advising customers to update or restrict administrative access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
