A red background with a white bug icon symbolizes a critical vulnerability. The text reads: Critical Vulnerability Impacting FortiOS and FortiProxy Systems (CVE-2024-55591) with Upwind logo in the top-right corner.

New CVE-2024-5591 Zero-Day Exploitation of Fortinet Firewalls 

Eliad Mualem January 14, 2025

New CVE-2024-5591 Zero-Day Exploitation of Fortinet Firewalls 

On January 14, 2025, Fortinet announced a critical vulnerability impacting its FortiOS and FortiProxy systems, CVE-2024-55591 is an authentication  bypass zero-day vulnerability that has been actively exploited since mid-November 2024, enabling attackers to hijack Fortinet firewalls and compromise enterprise networks. Successful exploitation grants remote attackers super-admin privileges via malicious requests to the Node.js websocket module.

Discovery and Response 

Fortinet and cybersecurity firm Arctic Wolf jointly identified this campaign, which involves unauthorized administrative access, creation of rogue accounts, and configuration changes. Exploited devices have exhibited activity such as new admin and local users added to VPN groups, changes to firewall policies, and SSL VPN tunneling through rogue accounts.

Fortinet has issued mitigation guidance, including disabling the HTTP/HTTPS administrative interface or restricting access to trusted IPs via local-in policies. Arctic Wolf highlighted that the attacks involved a rapid sequence of phases, starting with vulnerability scanning in November 2024 and culminating in lateral movement by late December 2024. 

CVE-2024-55591 Impact 

Exploitation of this zero-day vulnerability involves remote authentication bypass, enabling  attackers to escalate privileges to super-admin. Compromised devices have been used for  account creation, policy manipulation, and VPN tunneling, with significant risk of  lateral movement across networks.

Fortinet and Arctic Wolf identified the following dates for the attack phases:

  • Vulnerability Scanning: November 16–23, 2024  
  • Reconnaissance: November 22–27, 2024  
  • SSL VPN Configuration: December 4–7, 2024  
  • Lateral Movement: December 16–27, 2024  

Affected Versions 

FortiOS  

  • Versions 7.0.0 through 7.0.16  
  • Versions 7.2.0 through 7.2.12  

Recommended fix: 

  • Upgrade to 7.0.17 or above 

FortiProxy  

  • Versions 7.0.0 through 7.0.19  
  • Versions 7.2.0 through 7.2.12 

Recommended fix:

  • Upgrade to 7.2.13 or above

Fortinet advises organizations to:  

  1. Disable HTTP/HTTPS administrative access or restrict access to trusted  IPs using local-in policies.
  2. Monitor logs for unauthorized logins, rogue account creation and unexpected policy changes.  
  3. Ensure firewall management interfaces are not exposed to the Internet.  
  4. Upgrade FortiOS to 7.0.17 or above and FortiProxy to 7.2.13 or above to mitigate CVE-2024-55591.  

Organizations should prioritize securing FortiGate firewalls and related devices to prevent further exploitation of this vulnerability.  For additional information or assistance with mitigation efforts, contact us at [email protected].

Contents

Further Reading

You Can't Crowdsource Your Way to a Live Adversary

You Can’t Crowdsource Your Way to a Live Adversary

Bug bounty programs were built on a single assumption: that finding a vulnerability was the hard, scarce, expensive part worth paying for. That assumption held for about a decade, then AI erased it. When anyone can point a model at your code and receive a plausible-looking finding back in seconds, a crowd of finders stops…
arrayref Supply Chain Attack

arrayref Supply Chain Attack: A One-Line Build Dependency Ran a Backdoor During cargo build

Key Takeaways Executive Summary arrayref 0.3.10 is a hijacked release of a widely used Rust utility crate that added one dependency, proc-macro1, whose build script downloaded and executed a remote binary at compile time. The release was live on crates.io for 86 minutes on August 20, 2026, alongside [email protected] and [email protected] published from the same…
Yuval_ArgoCD Research

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover 

Executive Summary  This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS