Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

CVE-2024-55591 -- CVSS 9.8 Vulnerability Briefing

CVE-2024-55591 | CVSS 9.8 (Critical) | Exploit: PoC available

What Is It

CVE-2024-55591 is an authentication bypass vulnerability in the Node.js websocket module used by Fortinet FortiOS and FortiProxy administrative interfaces.

Technical Detail

The flaw is classified as Authentication Bypass Using an Alternate Path or Channel, CWE-288. A remote attacker can send crafted requests to the affected Node.js websocket module to bypass authentication and obtain super-admin privileges. Successful exploitation provides full administrative control of the affected FortiOS or FortiProxy appliance.

Exploitation Status

A proof of concept is available. CISA has not listed this vulnerability in its Known Exploited Vulnerabilities Catalog, and active exploitation in the wild is not confirmed by the provided data.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Treat this as a critical patching priority. Upgrade FortiOS 7.0 deployments to version 7.0.17 or later, FortiProxy 7.0 deployments to version 7.0.20 or later, and FortiProxy 7.2 deployments to version 7.2.13 or later. Until updates are installed, restrict administrative HTTP and HTTPS access to trusted management networks only, remove Internet exposure from management interfaces where possible, and review appliance logs for unexpected administrator logins, newly created administrative accounts, configuration changes, or unusual websocket-related requests.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →