Critical Vulnerability In FortiOS And FortiProxy (CVE-2024-55591)
CVSSv3 Score: Base 9.8 Critical
BACKGROUND
Fortinet has identified a severe vulnerability in FortiOS and FortiProxy that allows unauthenticated
remote attackers to bypass authentication mechanisms and gain “super-admin” privileges.
Threat actors have been observed performing malicious post-exploitation activities, including the
creation of random administrative and local user accounts, modification of system configurations
(e.g., firewall policies), and the use of SSL VPN for unauthorized access to internal network.
IMPACT
- Attackers can create new administrative and local user accounts with random usernames, resulting in unauthorized access.
- Attackers can access the SSL VPN with newly created local user accounts to establish a connection to the internal network.
- Attackers can gain control of the affected system and perform administrative tasks such as:
o Adding users to existing or new SSL VPN user groups
o Modifying configurations, including SSL VPN settings
o Adding or changing firewall policies
o Altering or removing system configurations
o Deploying malicious payloads
AFFECTED PRODUCTS
| Product | Affected Versions | |
| 1 | FortiOS | 7.0.0 through 7.0.16 |
| 2 | FortiProxy | 7.0.0 through 7.0.19 |
| 3 | FortiProxy | 7.2.0 through 7.2.12 |
RECOMMENDATIONS
- Upgrade the affected versions to the fixed versions as soon as possible.
- If immediate updates are not possible, implement the following workarounds:
- Disable HTTP/HTTPS administrative interface or limit IP Addresses that can reach the administrative interface via local-in policies.
- Remove the firewall’s web-based management interface from the public internet.
- Ensure all connections to the device are monitored, and that audit logging for the device is enabled.
- If required for operations, use ACLs to limit what IP addresses can access the port. This can be done directly on the device via the "my_allowed_addresses" configuration setting.
Note: Detailed recommended steps to follow can be found in Fortinet’s website at https://fortiguard.fortinet.com/psirt/FG-IR-24-535
REFERENCES
https://fortiguard.fortinet.com/psirt/FG-IR-24-535
https://nvd.nist.gov/vuln/detail/CVE-2024-55591
https://www.linkedin.com/pulse/fortinet-patches-zero-day-vulnerability-fortios-eotxe/