RaqibCTI
CVE

CVE-2024-55591

P1⬤ KNOWN RANSOMWARE USE
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet · FortiOS and FortiProxy
Date added (CISA)
2025-01-14
Remediation due
2025-01-21
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16

Description

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Source: NVD ↗ · CISA KEV Catalog ↗