- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Authentication bypass in Node.js websocket module
Hi FGT/FPX admins
Regarding the latest security incident, IR number FG-IR-24-535 // CVE ID CVE-2024-55591, that affected some FortiOS versions.
https://www.fortiguard.com/psirt/FG-IR-24-535
Additionally to the remediation actions described on the PSIRT page, you may check if your IP address is affected (published by some third parties) and take the appropriate action if so.
- Labels:
-
FortiGate
-
FortiProxy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Abdlekrim,
I hope you are doing well!
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello AEK,
May know your current fortigate Firmware version, due to this Vulvulnerability, only affected on the version 7.0.0 through 7.0.16, from version FortiOS 7.2 to latest version is not affected.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Mohan & Anthony
Thanks for your feedback.
This post was actually not a question. It was just to share an info for admins who want to check if their IP addresses are affected by the attack.
