CISA Known Exploited Vulnerability (KEV)
Fortinet FortiOS Authorization Bypass Vulnerability
January 14, 2025
January 21, 2025
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-288 |
Authentication Bypass Using an Alternate Path or Channel |