CVE-2024-55591
A critical flaw in FortiOS and FortiProxy lets attackers gain super‑admin rights by sending specially crafted requests to a Node.js websocket module. The vulnerability is easy to exploit and can be used to take full control of the affected device.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
FortiOS 7.0.0‑7.0.16 and FortiProxy 7.0.0‑7.0.19 and 7.2.0‑7.2.12. Users running these versions on network devices such as firewalls or proxies are at risk.
Real-world impact
An attacker could take complete control of the device, read or modify any data, install malware, or disrupt network services.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited remotely without authentication, gives full confidentiality, integrity, and availability compromise, and requires no user interaction.
What to do about it
- 011. Review the vendor’s mitigation guidance for the affected FortiOS or FortiProxy version.
- 022. Apply the recommended configuration changes or install the vendor‑issued patch.
- 033. Restart the affected services or device to ensure the changes take effect.
- ›If a patch or configuration change is not available, discontinue use of the affected product until a fix is released.
CISA KEV required action
Timeline
- Jan 14, 2025 · Jan 14, 2025Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jan 14, 2025 · Jan 14, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jan 21, 2025 · Jan 21, 2025CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 5, 2026 · 19h agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 17h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- fortiguard.fortinet.com/psirt/FG-IR-24-535mitigationvendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource