CVE-2024-55594: Web application firewall rules bypass by using an empty filename
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.
Other sources
Two improper handling of syntactically invalid structure vulnerabilities [CWE-228] in FortiWeb may allow an unauthenticated attacker to bypass web firewall protections via HTTP/S crafted requests.
— FortiGuard
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What versions of Fortinet FortiWeb are affected by CVE-2024-55594?
CVE-2024-55594 affects Fortinet FortiWeb versions 7.4.0 to 7.4.6, 7.2.0 to 7.2.10, and 7.0.0 to 7.0.10.
What is the severity of CVE-2024-55594?
CVE-2024-55594 has a high severity rating due to its potential to allow unauthorized code execution.
How do I fix CVE-2024-55594?
To mitigate CVE-2024-55594, users should update Fortinet FortiWeb to the latest unaffected version.
What kind of attack can exploit CVE-2024-55594?
CVE-2024-55594 can be exploited through crafted HTTP/S requests that trigger improper handling of invalid structures.
Is there a workaround for CVE-2024-55594 if I cannot update immediately?
Currently, there are no recommended workarounds for CVE-2024-55594, so updating to a patched version is strongly advised.