Target Industry
Indiscriminate, opportunistic targeting.
Overview
Fortinet has issued a security advisory concerning a critical authentication bypass vulnerability in specific versions of its FortiOS and FortiProxy products. This severe flaw, now designated as CVE-2024-55591 with an CVSS score of 9.6, has the potential to allow remote attackers to gain super-admin privileges on the affected appliances.
Impact
Exploitation of this vulnerability could lead to a complete compromise of the affected systems. Attackers could potentially control network security infrastructure, modify configurations, access sensitive data, and pivot to other parts of the network, causing widespread damage. Notably, this vulnerability requires no user interaction and can be exploited remotely without any existing privileges, making it highly severe and easily exploitable.
Vulnerability Detection
- All users running versions of FortiOS 7.0.0 – 7.0.16 are vulnerable.
- All users running versions of FortiProxy 7.0.0 – 7.0.19, 7.2.0 – 7.2.12 are vulnerable.
Exploitation
The vulnerability is actively being exploited in the wild and was added to the CISA Known Exploited Vulnerability list. One proof-of-concept exploit is available on github.com.
Containment, Mitigations & Remediations
Patches are available for this vulnerability. FortiOS users should update to a version newer than 7.0.16. FortiProxy users should update to a version newer than 7.0.19 for the 7.0.x branch or newer than 7.2.12 for the 7.2.x branch.
Threat Landscape
Fortinet occupies a significant proportion of the networking-hardware market share. Given that threat actors generally utilise a combination of probability and asset value to determine which attack surfaces to develop exploits for, Fortinet networking hardware products have emerged as a prime target for threat actors. Due to the fact that Fortinet products have become an integral aspect of business operations, threat actors will continue to exploit vulnerabilities these product types in an attempt to exfiltrate sensitive data contained therein or impact associated business operations.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.
Further Information
1. https://nvd.nist.gov/vuln/












