Vulnerability threat dossier

CVE-2024-55591

fortinetfortiproxy

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

VTP deterministic threat61.6of 100 · CVSS excluded

VTP analyst assessment

FortiOS and FortiProxy authentication bypass

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

Critical alternate-path authentication bypass in specified FortiOS and FortiProxy versions permits remote attackers to obtain super-admin privileges through crafted Node.js WebSocket requests. Public known exploitation and known ransomware-campaign use are recorded; VTP observation is unknown.

Why it matters

  • Unauthenticated super-admin access enables broad control of an affected security appliance.
  • The 0.98259 EPSS score is predictive context only.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The supplied evidence does not identify specific actors, request signatures, or campaign prevalence for this CVE.

No first-party telemetry is configured.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Administrative WebSocket requests from untrusted sources.

AI baseline history (2)
  1. BASELINE ASSESSED
    FortiOS and FortiProxy authentication bypassgpt-5.6-sol · high
  2. BASELINE ASSESSED
    FortiOS and FortiProxy authentication bypassgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.98100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.98; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

3publications detected
3underlying evidence chains

1 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2024-55591ACTIVE
Evidence
04

Event history

Threat timeline

  1. 00:0014 Jan
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

  2. 00:0014 Jan
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

US and South Korea warn of Gunra ransomware targeting govt agencies

U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]

CVE-2024-55591CVE-2025-24472
Separate evidence group
Original

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.

CVE-2024-55591CVE-2025-24472
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2024-55591

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2024-55591
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score61.6vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.65 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-288
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.