{"id":"CVE-2024-55591","title":"An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain supe…","summary":"An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain supe…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-288"],"vendor":"fortinet","product":"fortiproxy","affected":["fortiproxy >= 7.0.0, < 7.0.20","fortiproxy >= 7.2.0, < 7.2.13","fortios >= 7.0.0, < 7.0.17"],"patched":["fortiproxy 7.2.13","fortios 7.0.17"],"published":"2025-01-14","updated":"2026-07-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-55591","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-24-535","label":"psirt@fortinet.com"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55591","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.98259,"epssPercentile":0.99914,"kev":true,"kevDateAdded":"2025-01-14","kevDueDate":"2025-01-21","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-07-08T14:51:15.607Z","exploits":{"github":9,"githubRepos":["https://github.com/watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591","https://github.com/sysirq/fortios-auth-bypass-poc-CVE-2024-55591","https://github.com/sysirq/fortios-auth-bypass-exploit-CVE-2024-55591"],"nuclei":["CVE-2024-55591"],"checkedAt":"2026-09-21T15:27:03.190Z"},"exploitAvailable":true,"slug":"CVE-2024-55591","body":"## Overview\n\nAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.\n\n## Affected\n\n- `fortiproxy >= 7.0.0, < 7.0.20`\n- `fortiproxy >= 7.2.0, < 7.2.13`\n- `fortios >= 7.0.0, < 7.0.17`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fortiproxy 7.2.13`\n- `fortios 7.0.17`","depth":"hadal","depthScore":100,"depthScoreParts":{"impact":53.9,"likelihood":19.7,"exploitation":25,"ransomware":5},"changes":[{"seq":4771,"id":"CVE-2024-55591","ts":1788887205343,"field":"exploit_available","old":"false","new":"true"},{"seq":3654,"id":"CVE-2024-55591","ts":1788886321956,"field":"exploit_available","old":"true","new":"false"},{"seq":2505,"id":"CVE-2024-55591","ts":1788882989700,"field":"exploit_available","old":"false","new":"true"},{"seq":1534,"id":"CVE-2024-55591","ts":1788882403551,"field":"exploit_available","old":"true","new":"false"},{"seq":648,"id":"CVE-2024-55591","ts":1788881841109,"field":"exploit_available","old":"false","new":"true"}]}