Authentication bypass using an alternate path or channel in FortiProxy and FortiOS - CVE-2025-24472,CVE-2024-55591
Published: January 14, 2025 / Updated: February 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper authentication within the Node.js websocket module in the web management interface. A remote non-authenticated attacker can bypass authentication and gain super-admin privileges on the system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
FortiOS
How to mitigate CVE-2025-24472,CVE-2024-55591
FortiOS - update to 7.0.17