Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

Authentication bypass in Node.js websocket module

Hi FGT/FPX admins

Regarding the latest security incident, IR number FG-IR-24-535 // CVE ID CVE-2024-55591, that affected some FortiOS versions.

https://www.fortiguard.com/psirt/FG-IR-24-535

Additionally to the remediation actions described on the PSIRT page, you may check if your IP address is affected (published by some third parties) and take the appropriate action if so.

AEK
AEK
3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello Abdlekrim,

 

I hope you are doing well!


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
kmohan
Staff
Staff

Hello AEK,

 

May know your current fortigate Firmware version, due to this Vulvulnerability, only affected on the version 7.0.0 through 7.0.16, from version FortiOS 7.2 to latest version is not affected.

 

Karthick
AEK
SuperUser
SuperUser

Hi Mohan & Anthony

Thanks for your feedback.

This post was actually not a question. It was just to share an info for admins who want to check if their IP addresses are affected by the attack.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors