>> All posts

CVE-2024-55591: Fortinet FortiOS authentication bypass to super-admin, actively exploited

The short version: FortiOS and FortiProxy have an authentication-bypass flaw (CVE-2024-55591) that lets a remote attacker reach super-admin by sending crafted requests to the Node.js websocket module. It scores 9.8, it's in CISA's KEV catalog, and it's been used in ransomware intrusions. If you run an affected build with an exposed management interface, patch and verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeCritical — in practice and on paper
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS~98% · 99.91th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2025-01-21
Known exploited?Yes — tied to ransomware activity (actor tracked as Mora_001), chained with CVE-2025-24472
Vulnerability typeCWE-288 authentication bypass via an alternate path → super-admin privileges
Requires authenticated session?No — pre-authentication
AffectedFortiOS 7.0.0–7.0.16; FortiProxy 7.0.0–7.0.19, 7.2.0–7.2.12
Fixed inFortiOS 7.0.17 · FortiProxy 7.0.20 · 7.2.13 and later

What you need to know

CVE-2024-55591 is an authentication bypass using an alternate path or channel: by crafting requests to the FortiOS/FortiProxy Node.js websocket module, a remote, unauthenticated attacker obtains super-admin access to the device.

  • It's the firewall's control plane. Super-admin on the perimeter device means the attacker controls the thing enforcing your policy — rules, traffic, and the boundary at once.
  • It's pre-authentication and network-reachable wherever the administrative/management interface is exposed.
  • It's been used in anger. Exploitation has been tied to ransomware operators, who paired it with a related bypass (CVE-2025-24472) to create rogue admin accounts and move in.

How serious we see it

Critical — on paper and in the real world.

Unauthenticated super-admin on an internet-facing firewall, confirmed used in ransomware intrusions, is top-of-queue. The bounded, reassuring part: it affects specific FortiOS 7.0.x and FortiProxy builds, the fixes are published, and exposure is quick to determine. The catch is the familiar one — check whether rogue admin accounts or config changes were made before you patched, because a fixed device isn't automatically a clean one.

Recommendations

Straight from Fortinet's advisory (FG-IR-24-535) and CISA:

  1. Patch now. Upgrade to FortiOS 7.0.17 / FortiProxy 7.0.20 / 7.2.13 or later.
  2. Hunt for rogue admins. Review admin accounts, config changes, and logs for unexpected additions made during the exposure window — a documented hallmark of this campaign.
  3. If you find indicators, respond fully. Remove rogue accounts, rebuild if warranted, and rotate all credentials, keys, and certificates.
  4. Harden exposure. Get the administrative interface off the public internet; restrict it to trusted networks.
  5. Confirm your exposure first. Verify whether you run an affected FortiOS/FortiProxy build with an exposed management interface.

How BreachRisk sees it

BreachRisk discovers internet-facing FortiGate management and SSL VPN interfaces from little more than your domain, fingerprints the FortiOS/FortiProxy version, and flags exposure tied to KEV-listed, actively exploited flaws like this one — surfaced at the top of your results because it's in KEV. Where authorized, it goes beyond detection and safely performs a bounded, non-disruptive check against the affected endpoint to confirm the bypass responds, rather than flagging a maybe.

That outside-in, continuous view means that when a firewall bypass is being used by ransomware crews, the exposed appliance is already mapped and ranked — you go straight to patch-and-verify.

References

See your cyber risk, proven.