Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fortinet | FortiOS | 7.0.0 ~ 7.0.16 | cpe:2.3:o:fortinet:fortios:7.0.16:*:*:*:*:*:*:* | |
| Fortinet | FortiProxy | 7.2.0 ~ 7.2.12 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591 | POC Details |
| 2 | Checks for authentication bypass vulnerability inFortinet's FortiOS, potentially exploited by remote attackers. | https://github.com/souzatyler/fortios-auth-bypass-check-CVE-2024-55591 | POC Details |
| 3 | None | https://github.com/sysirq/fortios-auth-bypass-poc-CVE-2024-55591 | POC Details |
| 4 | None | https://github.com/sysirq/fortios-auth-bypass-exploit-CVE-2024-55591 | POC Details |
| 5 | Private CVE-2024-55591 | https://github.com/amfg145/Private-CVE-2024-55591. | POC Details |
| 6 | CVE-2024-55591 Opening CMD (Command Line Interface), Creating a Superuser, and Managing VPN Groups | https://github.com/robomusk52/exp-cmd-add-admin-vpn-CVE-2024-55591 | POC Details |
| 7 | None | https://github.com/watchtowrlabs/fortios-auth-bypass-poc-CVE-2024-55591 | POC Details |
| 8 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | https://github.com/virus-or-not/CVE-2024-55591 | POC Details |
| 9 | A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability (CVE-2024-55591) in certain Fortinet devices. | https://github.com/exfil0/CVE-2024-55591-POC | POC Details |
| 10 | #PoC for CVE-2024-55591 Authentication bypass Affects: FortiOS 7.0.0 to 7.0.16 , FortiProxy 7.0.0 to 7.0.19 ,FortiProxy 7.2.0 to 7.2.12 | https://github.com/rawtips/CVE-2024-55591 | POC Details |
| 11 | None | https://github.com/0x7556/CVE-2024-55591 | POC Details |
| 12 | None | https://github.com/binarywarm/exp-cmd-add-admin-vpn-CVE-2024-55591 | POC Details |
| 13 | Fortinet FortiOS is vulnerable to an information disclosure via service-worker.js that could allow an attacker to access sensitive information.This vulnerability affects FortiOS and could potentially lead to unauthorized access to the system. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-55591.yaml | POC Details |
| 14 | None | https://github.com/UMChacker/CVE-2024-55591-POC | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-37936 | 9.6 CRITICAL | Fortinet FortiSwitch 安全漏洞 |
| CVE-2023-37931 | 8.6 HIGH | Fortinet FortiVoice Entreprise SQL注入漏洞 |
| CVE-2024-35277 | 8.4 HIGH | Fortinet FortiPortal和Fortinet FortiManager 访问控制错误漏洞 |
| CVE-2024-47572 | 8.3 HIGH | Fortinet FortiSOAR 安全漏洞 |
| CVE-2024-27778 | 8.3 HIGH | Fortinet FortiSandbox 操作系统命令注入漏洞 |
| CVE-2024-48886 | 8.0 HIGH | Fortinet FortiOS 安全漏洞 |
| CVE-2024-47571 | 7.9 HIGH | Fortinet FortiManager 安全漏洞 |
| CVE-2024-23106 | 7.7 HIGH | Fortinet FortiClientEMS 安全漏洞 |
| CVE-2023-37937 | 7.6 HIGH | Fortinet FortiSwitch 操作系统命令注入漏洞 |
| CVE-2024-46670 | 7.5 HIGH | Fortinet FortiOS 缓冲区错误漏洞 |
| CVE-2024-50566 | 7.2 HIGH | Fortinet FortiManager 操作系统命令注入漏洞 |
| CVE-2024-46668 | 7.1 HIGH | Fortinet FortiOS 安全漏洞 |
| CVE-2024-48884 | 7.1 HIGH | Fortinet多款产品 路径遍历漏洞 |
| CVE-2024-36512 | 7.0 HIGH | Fortinet FortiManager和FortiAnalyzer 路径遍历漏洞 |
| CVE-2024-35273 | 7.0 HIGH | Fortinet FortiManager和Fortinet FortiAnalyzer 缓冲区错误漏洞 |
| CVE-2024-46667 | 6.9 MEDIUM | Fortinet FortiSIEM 安全漏洞 |
| CVE-2024-33503 | 6.7 MEDIUM | Fortinet FortiManager和FortiAnalyzer 安全漏洞 |
| CVE-2024-56497 | 6.5 MEDIUM | Fortinet FortiMail和FortiRecorder 操作系统命令注入漏洞 |
| CVE-2024-35275 | 6.5 MEDIUM | Fortinet FortiManager和Fortinet FortiAnalyzer SQL注入漏洞 |
| CVE-2024-33502 | 6.4 MEDIUM | Fortinet FortiManager和FortiAnalyzer 路径遍历漏洞 |
Showing top 20 of 47 CVEs. View all on vendor page → →
No comments yet