CVE-2024-55591

Fortinet OS & FortiProxy Authentication Bypass Vulnerability (CVE-2024-55591) Notification

January 16, 2025

Overview Recently, NSFOCUS CERT detected that Fortinet has issued a security notification and fixed the identity authentication bypass vulnerability in FortiOS and FortiProxy (CVE-2024-55591). Unauthenticated attackers can bypass system identity authentication by sending special packets to the Node.js websocket module, thus obtaining super administrator permissions of the target system. The CVSS score is 9.8. At […]

Search

Subscribe to the NSFOCUS Blog