Fortinet Zero-Day CVE-2024-55591: Super-Admin Risk
ID: 41ba07e8-0dd2-5020-b162-6d3a4d238a49
STIX ID: report--41ba07e8-0dd2-5020-b162-6d3a4d238a49
Feed Name: Cyble Blog
Threat Score
Fortinet disclosed CVE-2024-55591, a critical authentication-bypass in FortiOS and FortiProxy (CVSSv3 9.6) exploited via the Node.js WebSocket module; attackers are observed gaining super-admin access, creating administrative/VPN accounts, and using SSL VPN to access internal networks. Fortinet lists affected versions, IoCs (suspicious IPs and log entries), and urgent mitigation steps including upgrading to fixed versions and tightening administrative access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
