VORANT. Threat Intelligence Sign in Get the full feed

FortiOS auth bypass CVE-2024-55591 exploited

high vulnerability

A FortiOS authentication bypass flaw (CVE-2024-55591) is being actively exploited, including confirmed attacks in Japan, to gain admin access.

IPA Japan issued an advisory on a Fortinet FortiOS vulnerability, CVE-2024-55591, which allows an unauthenticated remote attacker to bypass authentication and obtain administrator privileges. Fortinet confirmed exploitation of this flaw in the wild at the time of initial disclosure in January 2025.

In a May 2025 update, IPA reported that attacks believed to exploit this vulnerability have been observed within Japan, and warned that damage could continue to spread. Fortinet has since added indicators of compromise to its advisory and released patched versions along with mitigation guidance. IPA urges affected organizations to apply vendor-provided updates or workarounds urgently and to use the published IoCs to check for signs of compromise.

Mentioned in this report

Vulnerabilities CVE-2024-55591KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20250115.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free