Get a Demo
Under Attack?
A red background with a white bug icon symbolizes a critical vulnerability. The text reads: Critical Vulnerability Impacting FortiOS and FortiProxy Systems (CVE-2024-55591) with Upwind logo in the top-right corner.

New CVE-2024-5591 Zero-Day Exploitation of Fortinet Firewalls 

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Eliad Mualem January 14, 2025

New CVE-2024-5591 Zero-Day Exploitation of Fortinet Firewalls 

On January 14, 2025, Fortinet announced a critical vulnerability impacting its FortiOS and FortiProxy systems, CVE-2024-55591 is an authentication  bypass zero-day vulnerability that has been actively exploited since mid-November 2024, enabling attackers to hijack Fortinet firewalls and compromise enterprise networks. Successful exploitation grants remote attackers super-admin privileges via malicious requests to the Node.js websocket module.

Discovery and Response 

Fortinet and cybersecurity firm Arctic Wolf jointly identified this campaign, which involves unauthorized administrative access, creation of rogue accounts, and configuration changes. Exploited devices have exhibited activity such as new admin and local users added to VPN groups, changes to firewall policies, and SSL VPN tunneling through rogue accounts.

Fortinet has issued mitigation guidance, including disabling the HTTP/HTTPS administrative interface or restricting access to trusted IPs via local-in policies. Arctic Wolf highlighted that the attacks involved a rapid sequence of phases, starting with vulnerability scanning in November 2024 and culminating in lateral movement by late December 2024. 

CVE-2024-55591 Impact 

Exploitation of this zero-day vulnerability involves remote authentication bypass, enabling  attackers to escalate privileges to super-admin. Compromised devices have been used for  account creation, policy manipulation, and VPN tunneling, with significant risk of  lateral movement across networks.

Fortinet and Arctic Wolf identified the following dates for the attack phases:

  • Vulnerability Scanning: November 16–23, 2024  
  • Reconnaissance: November 22–27, 2024  
  • SSL VPN Configuration: December 4–7, 2024  
  • Lateral Movement: December 16–27, 2024  

Affected Versions 

FortiOS  

  • Versions 7.0.0 through 7.0.16  
  • Versions 7.2.0 through 7.2.12  

Recommended fix: 

  • Upgrade to 7.0.17 or above 

FortiProxy  

  • Versions 7.0.0 through 7.0.19  
  • Versions 7.2.0 through 7.2.12 

Recommended fix:

  • Upgrade to 7.2.13 or above

Fortinet advises organizations to:  

  1. Disable HTTP/HTTPS administrative access or restrict access to trusted  IPs using local-in policies.
  2. Monitor logs for unauthorized logins, rogue account creation and unexpected policy changes.  
  3. Ensure firewall management interfaces are not exposed to the Internet.  
  4. Upgrade FortiOS to 7.0.17 or above and FortiProxy to 7.2.13 or above to mitigate CVE-2024-55591.  

Organizations should prioritize securing FortiGate firewalls and related devices to prevent further exploitation of this vulnerability.  For additional information or assistance with mitigation efforts, contact us at [email protected].

Contents

Further Reading

upwind-identities

Introducing the Upwind Identity Graph: End-to-End Identity Security

Identity used to be treated as a directory problem: find the user, inspect the groups, review the assigned roles, and decide whether the account has too much access. That model no longer matches the cloud. A single person may authenticate through Okta, inherit permissions from multiple groups, receive role assignments in more than one cloud,…
AI-Graph

Introducing the Upwind AI Graph: Extending AI Inventory Beyond Cloud Infrastructure

As enterprise adoption of artificial intelligence accelerates, modern AI infrastructure has expanded far beyond traditional cloud perimeters. Securing enterprise AI today requires complete visibility across four distinct operational layers: Traditional cloud security tools stop at the cloud provider boundary. When enterprise teams connect directly to external AI Providers, security teams lose sight of access paths,…
ChatGPT Image Aug 4, 2026, 08_46_20 AM

Keyv Supply Chain Compromise: An npm Worm That Takes Its Orders From an Ethereum Smart Contract

Executive Summary On August 4, 2026 at 09:35 UTC, [email protected] was published to npm carrying a credential stealer, an npm worm, and a persistence mechanism designed to detonate during incident response.  Keyv ranks #274 by npm reach and is present in 84,759 customer environments, and the release shipped with valid GitHub OIDC provenance and a…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS