Hi, I read the CVE article below and wonder if I need to upgrade FortiOS:
Fortinet Security Advisory: FG-IR-24-535
My FortiOS version is 7.0.16, and the HTTP/HTTPS administrative interface is enabled only on the LAN interface (disabled on the WAN interface).
Do I need to upgrade FortiOS to protect against this vulnerability?
Solved! Go to Solution.
Even if HTTP/HTTPS is enabled in a LAN interface, there is still a risk of exposure since that vulnerability can be exploited from the internal interface.
I would suggest to apply local-in policies as provided in the 'Workaround' section in (https://fortiguard.fortinet.com/psirt/FG-IR-24-535) where you will specify the addresses allowed to communicate to that interface for administration purposes internally.
Alternatively you can upgrade to 7.0.17 where the vulnerability is patched.
Even if HTTP/HTTPS is enabled in a LAN interface, there is still a risk of exposure since that vulnerability can be exploited from the internal interface.
I would suggest to apply local-in policies as provided in the 'Workaround' section in (https://fortiguard.fortinet.com/psirt/FG-IR-24-535) where you will specify the addresses allowed to communicate to that interface for administration purposes internally.
Alternatively you can upgrade to 7.0.17 where the vulnerability is patched.
Hi,Hatibi. Thank you for replay.
> Even if HTTP/HTTPS is enabled in a LAN interface, there is still a risk of exposure since that vulnerability can be exploited from the internal interface.
I forgot that the risk of exposures from internal interface.
Thank you.
Hi @studentuser ,
The vulnerability CVE-2024-55591 is in our PSIRT FG-IR-24-535. For more info please check this:
https://fortiguard.fortinet.com/psirt/FG-IR-24-535
The Severity is Critical. So I would recommend you upgrade the FortiGate to fix this vulnerability.
At least, you should apply the workaround as soon as possible.
@dingjerry_FTNT wrote:Hi @studentuser ,
The vulnerability CVE-2024-55591 is in our PSIRT FG-IR-24-535. For more info please check this:
https://fortiguard.fortinet.com/psirt/FG-IR-24-535
The Severity is Critical. So I would recommend you upgrade the FortiGate to fix this vulnerability.
At least, you should apply the workaround as soon as possible.
Hi dingjerry_FTNT,
I've already read its articles and I've looked up at more informartion. I understand it and I decide to upgrade FortiOS as soon as possible. Thank you for your reply.
Best Regards.
User | Count |
---|---|
2538 | |
1351 | |
795 | |
642 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.