CVE-2025-24472

Published Feb 11, 2025

Last updated 2 months ago

Exploit knownCVSS high 8.1
Fortinet
FortiOS
FortiProxy
VPN

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-24472 is an authentication bypass vulnerability found in Fortinet's FortiOS and FortiProxy products. It allows unauthorized remote attackers to gain super-admin privileges by sending specially crafted requests to the system's CSF proxy. The affected versions are FortiOS 7.0.0 through 7.0.16, FortiProxy 7.0.0 through 7.0.19, and FortiProxy 7.2.0 through 7.2.12. Fortinet has addressed this vulnerability; users should update to FortiOS 7.0.17 or later, and FortiProxy 7.0.20/7.2.13 or later. This vulnerability was disclosed on February 11, 2025, and added to an existing advisory regarding another authentication bypass vulnerability, CVE-2024-55591, which affected the same Fortinet products. While initial reports indicated active exploitation, Fortinet clarified that CVE-2025-24472 itself has not been seen exploited in the wild, although CVE-2024-55591 has been. Patches for both vulnerabilities are available, and users who had previously patched their systems against CVE-2024-55591 are already protected against CVE-2025-24472. Workarounds such as disabling the HTTP/HTTPS administrative interface or restricting access to it by IP address are also available.

Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.
Source
psirt@fortinet.com
NVD status
Analyzed
Products
fortiproxy, fortios

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Exploit added on
Mar 18, 2025
Exploit action due
Apr 8, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

psirt@fortinet.com
CWE-288

Social media

Hype score
Not currently trending
  1. CISA and FBI warn of Gunra ransomware exploiting CVE-2024-55591 & CVE-2025-24472 on edge devices, followed by log wiping and double extortion. Patch perimeter assets and ship telemetry off-box. Advisory https://t.co/E2uAJb9qhq https://t.co/QC14eBVf0C

    @2Workly

    22 Sept 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA named the group hunting hospitals through Fortinet holes. Ask your IT company if CVE-2024-55591 and CVE-2025-24472 are patched. Then ask who owns the risk analysis. Those are two different jobs. Only one of them is usually in the MSP contract.

    @jvjinfinity

    20 Aug 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CISA, the FBI, NSA and Secret Service warn that Gunra ransomware affiliates are actively exploiting unpatched Fortinet FortiOS and FortiProxy flaws CVE-2024-55591 and CVE-2025-24472 to break into healthcare, financial and government networks worldwide. https://t.co/wtPvvZIiQp

    @ShortInfoNews

    15 Aug 2026

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Gunra ransomware gang launched formal RaaS platform in January 2026 and is actively recruiting penetration testers and ethical hackers as initial access brokers for enterprise network access. US, South Korea agencies warn the group exploits CVE-2024-55591 and CVE-2025-24472

    @Milwyn1

    14 Aug 2026

    82 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Campaña de Gunra ataca dispositivos Fortinet explotando CVE-2024-55591 y CVE-2025-24472 para evadir MFA, elevar privilegios y acceder a redes empresariales. Mas información: https://t.co/vloCGRsoWC #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/D2pZ

    @EcuCERT_EC

    14 Aug 2026

    190 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Gunra ransomware, a Conti-based RaaS also operating as "Golden Community," is exploiting CVE-2024-55591 and CVE-2025-24472 in FortiOS/FortiProxy to hit government and critical infrastructure. #DFIR_Radar https://t.co/WBeTSTKvdr

    @DFIR_Radar

    12 Aug 2026

    128 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Gunra ransomware actors exploited CVE-2024-55591 and CVE-2025-24472 to bypass MFA on Fortinet appliances, then compromised identity infrastructure for lateral movement. Runtime segmentation helps contain post-compromise activity when perimeter defenses fail. #ZeroTrust 🔗 Full

    @aviatrixtrc

    12 Aug 2026

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Fortinet nigdy nie zawodzi… 😅 🔴 CVE-2024-55591 — 9.8 CRITICAL 🟠 CVE-2025-24472 — 8.1 HIGH Podatności w FortiOS/FortiProxy są wykorzystywane w atakach. Warto sprawdzić wersję i aktualizacje. #Fortinet #FortiGate #CVE #CyberSecurity https://t.co/nQESAuEON8

    @marekitlab

    12 Aug 2026

    163 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    2 Quotes

  9. Gunra ransomware exploited critical Fortinet authentication bypass flaws (CVE-2024-55591, CVE-2025-24472) to escalate to super-admin privileges and move laterally across government networks. Runtime segmentation helps contain post-compromise activity when perimeter defenses fail.

    @aviatrixtrc

    12 Aug 2026

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Joint CSA: Gunra ransomware (CISA/FBI/NSA + allies). RaaS double-extortion on gov and critical infrastructure. Edge: FortiOS/FortiProxy CVE-2024-55591 / CVE-2025-24472. Patch exposed VPN/edge. Segment. Test offline immutable backups. https://t.co/xVWEqWnejC

    @snypet86

    12 Aug 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. US, South Korea and allied agencies warn: Gunra ransomware is breaching critical infrastructure via Fortinet (CVE-2025-24472) and Schneider Electric (CVE-2024-5559) edge flaws, then defeating MFA at the VDI portal. Patch your edge. #ransomware #Fortinet

    @JNitterauer

    11 Aug 2026

    191 Impressions

    1 Retweet

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  12. Gunra Linux ransomware bakes in weak key derivation that lets anyone with a sample pull the full Salsa20 or ChaCha20 key in seconds. Access starts with CVE-2024-5559 on Schneider Electric PowerLogic P5 and CVE-2025-24472 on FortiOS 7.2.0–7.4.4 plus FortiProxy. RaaS panel hands

    @SecureChap

    11 Aug 2026

    65 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  13. FortiGate admins: CISA says Gunra is exploiting CVE-2024-55591 and CVE-2025-24472 to bypass MFA and steal data. PATCH. Review admin accounts, VPN logs, and configs now. https://t.co/AiSVOb4rJB

    @Techsico_IT

    11 Aug 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Gunra ransomware, a Conti-derived RaaS now operating globally, exploits FortiOS/FortiProxy auth bypasses and VPN default creds to hit healthcare, government, critical manufacturing and more across six regions. Key findings: - Initial access via CVE-2024-55591 and CVE-2025-24472

    @DFIR_Radar

    11 Aug 2026

    206 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  15. Gunra ransomware, built on leaked Conti source code, exploits FortiOS auth-bypass flaws CVE-2024-55591 and CVE-2025-24472 to plant superuser accounts before deploying ChaCha20+RSA-4096 encryption and appending .ENCRT. #DFIR_Radar https://t.co/98DUE3D73L

    @DFIR_Radar

    11 Aug 2026

    123 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  16. 🚨 CVE-2025-24472 — now actively exploited in the wild (CISA KEV). An Authentication Bypass Using an Alternat… Risk 51/100 · EPSS 3% · CVSS 8.1. Patch or mitigate now — attackers are already using it. https://t.co/81Q7LdzuJA #KEV #CVE #Fortinet #AuthBypass #ActivelyE

    @BytesNora

    8 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. SuperBlack exploits CVE-2024-55591 and CVE-2025-24472 in Fortinet systems. AI ShieldNet uses behavioral AI to detect and stop zero-day attacks like this. Website: https://t.co/eeFYunNtwv #Cybersecurity #AIShieldNet #prosfinity https://t.co/Du0dl8F8rR

    @prosfinity

    10 Jun 2025

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Fortinetの脆弱性(CVE-2024-55591,CVE-2025-24472)を狙うサイバー攻撃が国内でも発生-JPCERTが警告 #セキュリティ対策Lab #セキュリティ #Security https://t.co/K2LlhH44nA

    @securityLab_jp

    9 May 2025

    68 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  19. Hey, did you hear? Hackers are getting SUPER-ADMIN access to Fortinet firewalls using CVE-2025-24472 & deploying "SuperBlack" ransomware. Patch ASAP! #cybersecurity https://t.co/7aQ6CFwzYs

    @storagetechnews

    4 Apr 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Actively exploited CVE : CVE-2025-24472

    @transilienceai

    3 Apr 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. Actively exploited CVE : CVE-2025-24472

    @transilienceai

    31 Mar 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  22. Actively exploited CVE : CVE-2025-24472

    @transilienceai

    27 Mar 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  23. 🚨 Fortinet has patched critical vulnerabilities (NCSC-2025-0082) in FortiOS, FortiProxy, FortiPAM, FortiSRA, and FortiWeb. Exploited in ransomware attacks, this flaw allows unauthorized code execution. Patch now! #CVE-2024-55591 #CVE-2025-24472 https://t.co/tPrTnAvPap

    @RedTeamNewsBlog

    24 Mar 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Actively exploited CVE : CVE-2025-24472

    @transilienceai

    21 Mar 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  25. FortiOS, FotiProxyの脆弱性の悪用が確認されているとのこと。 CVE-2025-24472 CVE-2024-55591 Fortinet Vulnerability Exploited in Ransomware Attack, CISA Warns - Infosecurity Magazine https://t.co/w3vcJozVFT

    @ntsuji

    21 Mar 2025

    6448 Impressions

    30 Retweets

    69 Likes

    18 Bookmarks

    2 Replies

    1 Quote

  26. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-24472 #Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability https://t.co/F6TsuBLDkl

    @ScyScan

    20 Mar 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🚨 Threat Alert: Fortinet CVE-2025-24472 Ransomware Exploitation 📅 Date: 2025-03-19 📌 Attribution: Mora_001 (potential ties to LockBit operations) 📝 Summary: A critical authentication bypass vulnerability (CVE-2025-24472) in Fortinet's FortiOS and FortiProxy technologies has…

    @syedaquib77

    20 Mar 2025

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. Actively exploited CVE : CVE-2025-24472

    @transilienceai

    20 Mar 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  29. 🔴 FortiOS, Authentication Bypass, #CVE-2025-24472 (Critical) https://t.co/B3nCMGjLX5

    @dailycve

    19 Mar 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🚨 Security Alert: CISA has issued a critical warning about a major vulnerability (CVE-2025-24472) in Fortinet’s FortiOS and FortiProxy systems. Remote attackers can exploit this flaw to gain super-admin access. 🔗 Read more: https://t.co/pJkREGY1By https://t.co/DZUfXOc8GU

    @Hosainfosec

    19 Mar 2025

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. CISA warns: Fortinet FortiOS auth bypass (CVE-2025-24472) exploited in the wild. Patches out, but why bother? With WEBOUNCER, no patching, no updates—just instant protection. #Cybersecurity #WEBOUNCER #impenetrable https://t.co/PZKJp781A8 via @The_Cyber_News

    @BrainLabVisions

    19 Mar 2025

    58 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  32. Ransomware Alert! Fortinet Under Siege: New ransomware gang SuperBlack exploits CVE-2024-55591 & CVE-2025-24472! CVE-2024-55591 – An Authentication bypass vulnerability affecting Fortinet's FortiOS and FortiProxy products. This flaw allows remote attackers to gain super-adm

    @Loginsoft_Inc

    19 Mar 2025

    79 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が、既知の悪用された脆弱性カタログに、FortiOS/FortiProxyの認証回避CVE-2025-24472とGitHub Action tj-actions/changed-filesの悪性コードCVE-2025-30066を追加。対応期限は通常の4/8。Fortiはランサムウェア悪用済。 https://t.co/JQnPJmC90H

    @__kokumoto

    18 Mar 2025

    1240 Impressions

    4 Retweets

    16 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  34. 🛡️ We added vulnerabilities for Fortinet FortiOS & FortiProxy, CVE-2025-24472, and GitHub, CVE-2025-30066, to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/bJOgGeWmb8 & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec htt

    @CISACyber

    18 Mar 2025

    11534 Impressions

    58 Retweets

    111 Likes

    17 Bookmarks

    5 Replies

    4 Quotes

  35. 🚨 Hackers linked to LockBit are exploiting Fortinet firewall vulnerabilities (CVE-2024-55591 & CVE-2025-24472) to deploy the SuperBlack ransomware. 🔹 Data is exfiltrated before encryption 🔹 Strong ties to LockBit 3.0 ransomware 🔹 Unpatched orgs remain at risk 📌 Patch NOW

    @the_aryanmittal

    17 Mar 2025

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. New ransomware group Mora_001 is exploiting Fortinet vulnerabilities (CVE-2024-55591, CVE-2025-24472), linked to LockBit. Affected devices may face threats if not patched. 🚨 #Fortinet #Ransomware #USA link: https://t.co/ddxsXkSqYa https://t.co/Sbhk3dsM1c

    @TweetThreatNews

    17 Mar 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  37. SuperBlack ransomware exploits Fortinet auth bypass flaws. The two vulnerabilities, both authentication bypasses, are CVE-2024-55591 and CVE-2025-24472, which Fortinet disclosed in January and February. https://t.co/D4e54UyCDn https://t.co/xjXCWZmSBr

    @riskigy

    16 Mar 2025

    74 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Cyber Alert : "SuperBlack ransomware is crashing the party, sneaking through Fortinet firewall holes (CVE-2024-55591, CVE-2025-24472)! A sneaky Russian hacker’s behind it, turning cyber chaos up to 11. Patch those systems fast—don’t let this villain steal the show!" #cybercrime

    @MohamedMar66543

    16 Mar 2025

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Threat Alert: Recent Fortinet Vulnerabilities Exploited in 'SuperBlack' Ransomware Attacks CVE-2024-55591 CVE-2025-24472 CVE-2025-2447 Severity: 🔴 High Maturity: 💥 Mainstream Learn more: https://t.co/sg0tFeoYVO #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    15 Mar 2025

    85 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  40. ⚠️ Vulnerability Alert: Authentication Bypass Vulnerabilities in Fortinet Firewalls 📅 Timeline: Disclosure: 2024-01-14, Patch: 2025-01-21 📌 Attribution: 🆔cveId: CVE-2024-55591, CVE-2025-24472 📊baseScore: 📏cvssMetrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H… https:

    @syedaquib77

    15 Mar 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. CVE-2024-55591 & CVE-2025-24472: Fortinet’s Double Vulnerability Nightmare https://t.co/vI63gkrOHW

    @Dinosn

    15 Mar 2025

    5915 Impressions

    39 Retweets

    104 Likes

    34 Bookmarks

    0 Replies

    1 Quote

  42. CVE-2024-55591 & CVE-2025-24472: Fortinet's Double Vulnerability Nightmare Forescout researchers have identified a new ransomware group, dubbed Mora_001, exploiting two critical vulnerabilities in Fortinet products to gain unauthorized access to firewalls https://t.co/wwPp7i

    @Daily_CyberSec

    15 Mar 2025

    924 Impressions

    4 Retweets

    14 Likes

    6 Bookmarks

    0 Replies

    1 Quote

  43. SuperBlack Ransomware Targets Fortinet Flaws Hackers exploit Fortinet CVE-2024-55591 & CVE-2025-24472 to gain super_admin access, steal data & deploy SuperBlack ransomware 🛑 Linked to LockBit, it erases forensic traces with WipeBlack! Patch now!⚠️ https://t.co/q8dvOPU

    @dCypherIO

    14 Mar 2025

    21 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  44. 🗞️ SuperBlack Ransomware Exploits Fortinet Auth Bypass Flaws in Targeted Attacks The new SuperBlack ransomware is exploiting Fortinet auth bypass flaws (CVE-2025-24472) to hit unpatched firewalls, with Forescout linking it to LockBit tactics. Over 23K vulnerable devices remain…

    @gossy_84

    14 Mar 2025

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. 🚨 SuperBlack ransomware is exploiting Fortinet vulnerabilities! 📌 CVE-2024-55591 & CVE-2025-24472 used for initial access 📌 Double extortion + custom wiper WipeBlack 📌 Uses LockBit’s leaked builder Patch your systems! Breaking news from the world &… https://t.co/ZF7G3

    @godeepweb

    14 Mar 2025

    37 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  46. Recent Fortinet Vulnerabilities Exploited in ‘SuperBlack’ Ransomware Attacks The newly discovered SuperBlack ransomware has been exploiting two vulnerabilities CVE-2024-55591 and CVE-2025-24472 in Fortinet firewalls. https://t.co/1TlLQtZmcC https://t.co/Pf5olgk4t6

    @persistsec

    14 Mar 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. According to Forescout, SuperBlack ransomware is exploiting CVE-2024-55591 and CVE-2025-24472, which target FortiGate 7.0.X management interfaces patched in Jan 2025. My latest investigation found over 30K vulnerable servers worldwide (Mgmt interface exposed, no patch applied). h

    @nekono_naha

    14 Mar 2025

    1333 Impressions

    4 Retweets

    9 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  48. 2025年1月に修正されたFortiGate7.0.X系の管理画面を対象としたCVE-2024-55591、CVE-2025-24472を悪用したSuperBlackランサム攻撃をForescout社が報告。調査した所、本日時点でもグローバルで23K台、国内1K台超の脆弱サーバを発見。なお、管理画面閉鎖、パッチ適用済み機器でも以下のような極めて面倒… https://t.co/FYC5CH9Lqq https://t.co/kpJ4Cr5M7f

    @nekono_naha

    14 Mar 2025

    3008 Impressions

    8 Retweets

    39 Likes

    18 Bookmarks

    0 Replies

    1 Quote

  49. A ransomware group, Mora_001, exploits Fortinet vulnerabilities CVE-2024-55591 and CVE-2025-24472 to deploy SuperBlack ransomware, with the latter confirmed exploited in attacks since February 2025, despite prior reassurances from Fortinet. #Security https://t.co/ARD6Z4X3bb

    @Strivehawk

    13 Mar 2025

    65 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  50. #threatreport #LowCompleteness Flash Notice: CVE-2025-24472 Actively Exploited - Patch and Manage | 03-03-2025 Source: https://t.co/PsbNnmQd6Y Key details below ↓ 🎯Victims: Fortinet 🔓CVEs: CVE-2024-55591 \[[Vulners](https://t.co/cNWxPVNtLL)] - CVSS V3.1: *9.8*, -… https:/

    @rst_cloud

    3 Mar 2025

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations