Back www.tenable.com Cve 2024 55591 Fortinet Authentication Bypass Zero Day Vulnerability Exploited In The Wild
Fortinet patched a zero day authentication bypass vulnerability in FortiOS and FortiProxy that has been actively exploited in the wild as a zero-day since November 2024.
Update February 11: The blog has been updated to include a new CVE issued by Fortinet, CVE-2025-24472
On January 14, Fortinet released a security advisory (FG-IR-24-535) addressing a critical severity vulnerability impacting FortiOS and FortiProxy .
On February 11, Fortinet updated their advisory to include an additional CVE, CVE-2025-24472. The description of the vulnerability itself was updated to include a new attack vector and the additional CVE was assigned a lower CVSSv3 score of 8.1.
CVE-2024-55591 and CVE-2025-24472 are authentication bypass vulnerabilities in FortiOS and FortiProxy. An unauthenticated, remote attacker could exploit these vulnerabilities by sending a specially crafted request to a Node.js websocket module or by sending specially crafted CSF proxy requests. Successful exploitation may grant an attacker super-admin privileges on a vulnerable device. According the Fortinet , CVE-2024-55591 has been exploited in the wild.
In the update to their advisory on February 11, Fortinet credited Sonny of watchTowr for reporting CVE-2025-24472, the newly added CVE to their February 11 update.
Zero Day Campaign May Have Been Active Since November
Researchers at Arctic Wolf published a blog post on January 10 detailing a campaign first observed in mid-November 2024 of suspicious activity related to the exploitation of a zero-day vulnerability, which is presumed to be CVE-2024-55591. Arctic Wolf Labs details four distinct phases of the campaign that were observed against Fortinet FortiGate firewall devices; scanning, reconnaissance, SSL VPN configuration and lateral movement. For more information on the observations of this campaign, we recommend reviewing its blog post.
At the time this blog was published, the Fortinet advisory did not credit Arctic Wolf with the discovery of CVE-2024-55591. However, the indicators of compromise (IoCs) listed in the Fortinet advisory overlap with the report from Arctic Wolf.
Historical exploitation of Fortinet FortiOS and FortiProxy
Fortinet FortiOS and FortiProxy have been targeted by threat actors previously, including targeting by advanced persistent threat (APT) actors. We’ve written several noteworthy Fortinet flaws since 2019, including flaws impacting SSL VPNs from Fortinet and other vendors:
CVE-2022-42475: Fortinet Patches Zero Day in FortiOS SSL VPNs
AA23-250A: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
At the time this blog post was published, there were no public proof-of-concept exploits for CVE-2024-55591.
Fortinet published its security advisory (FG-IR-24-535) on January 14 to address this vulnerability. The advisory also contains IoCs and workaround steps that can be utilized if immediate patching is not feasible. Fortinet has released the following patches for FortiOS and FortiProxy.
Fortinet also released several additional security advisories on January 14 for vulnerabilities affecting FortiOS and FortiProxy:
A list of Tenable plugins for this vulnerability can be found on the individual CVE pages for CVE-2024-55591 and CVE-2025-24472 as they’re released. This link will display all available plugins for this vulnerability, including upcoming plugins in our Plugins Pipeline .
Additionally, customers can utilize Tenable Attack Surface Management to identify public facing Fortinet assets:
Update February 11: The blog has been updated to include a new CVE issued by Fortinet, CVE-2025-24472
Join Tenable's Security Response Team on the Tenable Community.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
