First published: Tue Jan 14 2025(Updated: )
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. Please note that reports show this is being exploited in the wild.
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiOS | >=7.0.0<=7.0.16 | |
Fortinet FortiProxy | >=7.2.0<=7.2.12 | |
Fortinet FortiProxy | >=7.0.0<=7.0.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.