CVE-2024-55599: DNS type 65 resource record requests bypass DNS filter
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS and FortiProxy may allow a remote unauthenticated user to bypass the DNS filter via Apple devices.
Other sources
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.2.11 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.8 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.1 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.4.9 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.2 - Upgrade
Upgrade
FortiSASEto a version that resolves this vulnerability.Fixed in 24.4.b
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55599?
The severity of CVE-2024-55599 has not been explicitly stated, but it may allow a remote unauthenticated user to bypass DNS filters, which poses significant risk.
How do I fix CVE-2024-55599?
To mitigate CVE-2024-55599, upgrade FortiOS and FortiProxy to the recommended versions: FortiOS to 7.6.1 or higher, and FortiProxy to 7.6.2 or higher.
Which versions of FortiOS are affected by CVE-2024-55599?
CVE-2024-55599 affects FortiOS versions 6.4.0 to 7.4.8 and versions prior to 7.0.
Is FortiProxy vulnerable to CVE-2024-55599?
Yes, FortiProxy versions 7.0 and above, specifically 7.2.0 to 7.4.8, are also affected by CVE-2024-55599.
What does CVE-2024-55599 exploit?
CVE-2024-55599 exploits an improperly implemented security check for standard DNS filtering capabilities.