Get a Demo
Under Attack?
A red background with a white bug icon symbolizes a critical vulnerability. The text reads: Critical Vulnerability Impacting FortiOS and FortiProxy Systems (CVE-2024-55591) with Upwind logo in the top-right corner.

New CVE-2024-5591 Zero-Day Exploitation of Fortinet Firewalls 

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Eliad Mualem January 14, 2025

New CVE-2024-5591 Zero-Day Exploitation of Fortinet Firewalls 

On January 14, 2025, Fortinet announced a critical vulnerability impacting its FortiOS and FortiProxy systems, CVE-2024-55591 is an authentication  bypass zero-day vulnerability that has been actively exploited since mid-November 2024, enabling attackers to hijack Fortinet firewalls and compromise enterprise networks. Successful exploitation grants remote attackers super-admin privileges via malicious requests to the Node.js websocket module.

Discovery and Response 

Fortinet and cybersecurity firm Arctic Wolf jointly identified this campaign, which involves unauthorized administrative access, creation of rogue accounts, and configuration changes. Exploited devices have exhibited activity such as new admin and local users added to VPN groups, changes to firewall policies, and SSL VPN tunneling through rogue accounts.

Fortinet has issued mitigation guidance, including disabling the HTTP/HTTPS administrative interface or restricting access to trusted IPs via local-in policies. Arctic Wolf highlighted that the attacks involved a rapid sequence of phases, starting with vulnerability scanning in November 2024 and culminating in lateral movement by late December 2024. 

CVE-2024-55591 Impact 

Exploitation of this zero-day vulnerability involves remote authentication bypass, enabling  attackers to escalate privileges to super-admin. Compromised devices have been used for  account creation, policy manipulation, and VPN tunneling, with significant risk of  lateral movement across networks.

Fortinet and Arctic Wolf identified the following dates for the attack phases:

  • Vulnerability Scanning: November 16–23, 2024  
  • Reconnaissance: November 22–27, 2024  
  • SSL VPN Configuration: December 4–7, 2024  
  • Lateral Movement: December 16–27, 2024  

Affected Versions 

FortiOS  

  • Versions 7.0.0 through 7.0.16  
  • Versions 7.2.0 through 7.2.12  

Recommended fix: 

  • Upgrade to 7.0.17 or above 

FortiProxy  

  • Versions 7.0.0 through 7.0.19  
  • Versions 7.2.0 through 7.2.12 

Recommended fix:

  • Upgrade to 7.2.13 or above

Fortinet advises organizations to:  

  1. Disable HTTP/HTTPS administrative access or restrict access to trusted  IPs using local-in policies.
  2. Monitor logs for unauthorized logins, rogue account creation and unexpected policy changes.  
  3. Ensure firewall management interfaces are not exposed to the Internet.  
  4. Upgrade FortiOS to 7.0.17 or above and FortiProxy to 7.2.13 or above to mitigate CVE-2024-55591.  

Organizations should prioritize securing FortiGate firewalls and related devices to prevent further exploitation of this vulnerability.  For additional information or assistance with mitigation efforts, contact us at [email protected].

Contents

Further Reading

The Risk Isn't What You Prompt, It's What You Built.

The Risk Isn’t What You Prompt, It’s What You Built

Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…
Upwind is a Visionary Leader in Frost & Sullivan report

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

We're excited to share that Frost & Sullivan has recognized Upwind as a Strong Visionary Leader in the Frost Radar™: Cloud/Application Runtime Security, 2026. This recognition highlights the company's innovation, growth, and leadership in the emerging Cloud-Native Application Detection and Response (CNADR) market. For us, the recognition is meaningful not simply because of where Upwind…
API Custom Threat Detection

Upwind brings Custom Detection Policies for APIs

Every API has a different risk profile. An internal billing endpoint and a public-facing authorization endpoint don't fail the same way. They don't get attacked the same way either. A generic ruleset can't account for that. Custom rules can, and now those rules can see sensitive data too. This new release brings two things together…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS