FAIL › dossier
FortiOS and FortiProxy
PRODUCT· dossier confidence 80%
FortiOS and FortiProxy products have demonstrated a concerning security track record with multiple critical vulnerabilities including unauthenticated RCE and authentication bypasses, requiring immediate remediation to mitigate potential risks.
PROFILE
CategoryproductWhat they doFortiOS and FortiProxy are network security and management products developed by Fortinet.
SECURITY POSTURE
FortiOS and FortiProxy have a history of critical vulnerabilities including unauthenticated remote code execution (RCE) and authentication bypasses, with multiple high-severity flaws actively exploited in the wild.
Notable failures
- CVE-2024-55591: Unauthenticated RCE via Node.js websocket module
- CVE-2025-24472: Unauthenticated RCE via crafted CSF proxy requests
- CVE-2018-13382: Password modification via SSL VPN portal
- CVE-2018-13383: Heap buffer overflow disrupting SSL VPN services
Patterns: repeated unauthenticated RCE vulnerabilities; authentication bypasses in critical components; SSL VPN service disruptions
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-01-14 | CVE-2024-55591 | critical | An unauthenticated remote attacker can bypass authentication to gain super-admin privileges on Fortinet FortiOS and FortiProxy via a Node.js websocket module flaw. |
| 2025-03-18 | CVE-2025-24472 | critical | A remote attacker can bypass authentication to gain super-admin privileges on Fortinet FortiOS and FortiProxy via crafted CSF proxy requests. |
| 2022-01-10 | CVE-2018-13382 | critical | Unauthenticated attackers could modify passwords on Fortinet SSL VPN portals due to improper authorization vulnerabilities, actively exploited in the wild and linked to ransomware activity. |
| 2022-01-10 | CVE-2018-13383 | critical | Fortinet's FortiOS and FortiProxy had a critical heap buffer overflow exploited in the wild, potentially disrupting SSL VPN services for logged-in users. |
Open questions: Fortinet's overall security posture beyond FortiOS/FortiProxy · Patch management effectiveness for these products
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-01 03:47:34.754171+00:00