Noticias

Severe
_
flaw
_
in
_
Fortinet
_
actively
_
exploited:
_
CVE-2024-55591

Trends

On January 14, 2025, (or yesterday, depending on when you read this), Fortinet in coordination with NIST made public a critical vulnerability in Fortinet, identified as CVE-2024-55591, affecting FortiOS and FortiProxy.

This vulnerability allows remote attackers to gain superadministrator privileges on compromised devices, such as firewalls and SSL VPNs. The flaw is exploited through malicious requests to the WebSocket module of Node.js, enabling unauthenticated access to the administration panels.

The vulnerability affects FortiOS versions from 7.0.0 to 7.0.16, and FortiProxy versions from 7.0.0 to 7.0.19 and from 7.2.0 to 7.2.12. It is important to note that the latest versions of these products are not affected, so customers who keep their systems updated are protected from this vulnerability. Fortinet has released patches to address the issue and strongly recommends that organizations apply the updates immediately.