Fortinet has patched an actively exploited zero-day authentication bypass flaw affecting its FortiOS and FortiProxy products, which attackers have been exploiting to gain super-administrative access to devices to conduct nefarious activities, including breaching corporate networks. Fortinet characterized the flaw, rated as critical and tracked as CVE-2024-55591 (CVSS 9.6), as an "authentication bypass using an alternate path or channel vulnerability" that "may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module," according to a FortiGuard Labs security advisory last week. Fortinet observed threat actors performing various malicious operations by exploiting the flaw. These activities included: creating an admin account on the device with a random user name; creating a local user account on the device with a random user name; creating a user group or adding a local user to an existing SSL VPN user group; adding and/or changing other settings, including firewall policy and/or firewall address; and logging in to the SSL VPN to get a tunnel to the internal network. Fortinet recommended that customers using affected products follow the recommended upgrade path on its website to mitigate the flaw. It also offered workaround options in its advisory. The first signs that something was amiss came earlier this month, when researchers at Arctic Wolf revealed that a zero-day flaw was likely to blame for a series of recent attacks on Fort...
Actively Exploited Fortinet Zero-Day Gives Attackers Super-Admin Privileges
Dark Reading
·Elizabeth Montalbano
·Published Jan 28, 2025
·Updated
Affected Software
4 affected components
Fortinet FortiOS
Fortinet FortiProxy
Fortinet FortiOS
Fortinet FortiProxy
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in Fortinet's FortiOS and FortiProxy products that is being actively exploited by attackers.
2
What security implications are discussed?
The security implications include unauthorized access as attackers can gain super-admin privileges on affected devices.
3
What products or software are affected?
The affected products are Fortinet FortiOS and Fortinet FortiProxy.
4
Has Fortinet issued a fix for the vulnerability?
Yes, Fortinet has patched the zero-day authentication bypass flaw.
5
What type of attack is being executed against the vulnerable products?
The attack involves exploiting the vulnerability to achieve super-administrative access to the devices.