CyberSec.Space Logo
CVEブラウザに戻る

CVE-2024-55591

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score42.0420%
EPSS Percentile87.18th
Published2025-01-14
Last Modified2026-07-08
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Affected Platforms (CPE)

📦
Fortinet

Fortiproxy

>= 7.0.0 and < 7.0.20>= 7.2.0 and < 7.2.13
💻
Fortinet

Fortios

>= 7.0.0 and < 7.0.17

References & Advisories

関連する脆弱性情報