Skip to main content
AEK
SuperUser
SuperUser
January 17, 2025
Question

Authentication bypass in Node.js websocket module

  • January 17, 2025
  • 3 replies
  • 2096 views

Hi FGT/FPX admins

Regarding the latest security incident, IR number FG-IR-24-535 // CVE ID CVE-2024-55591, that affected some FortiOS versions.

https://www.fortiguard.com/psirt/FG-IR-24-535

Additionally to the remediation actions described on the PSIRT page, you may check if your IP address is affected (published by some third parties) and take the appropriate action if so.

3 replies

Anthony_E
Staff
Staff
January 20, 2025

Hello Abdlekrim,

 

I hope you are doing well!


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
kmohan
Staff
Staff
January 20, 2025

Hello AEK,

 

May know your current fortigate Firmware version, due to this Vulvulnerability, only affected on the version 7.0.0 through 7.0.16, from version FortiOS 7.2 to latest version is not affected.

 

AEK
SuperUser
AEKAuthor
SuperUser
January 20, 2025

Hi Mohan & Anthony

Thanks for your feedback.

This post was actually not a question. It was just to share an info for admins who want to check if their IP addresses are affected by the attack.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!