CVE-2025-24472
Published Feb 11, 2025
Last updated 2 months ago
AI description
CVE-2025-24472 is an authentication bypass vulnerability found in Fortinet's FortiOS and FortiProxy products. It allows unauthorized remote attackers to gain super-admin privileges by sending specially crafted requests to the system's CSF proxy. The affected versions are FortiOS 7.0.0 through 7.0.16, FortiProxy 7.0.0 through 7.0.19, and FortiProxy 7.2.0 through 7.2.12. Fortinet has addressed this vulnerability; users should update to FortiOS 7.0.17 or later, and FortiProxy 7.0.20/7.2.13 or later. This vulnerability was disclosed on February 11, 2025, and added to an existing advisory regarding another authentication bypass vulnerability, CVE-2024-55591, which affected the same Fortinet products. While initial reports indicated active exploitation, Fortinet clarified that CVE-2025-24472 itself has not been seen exploited in the wild, although CVE-2024-55591 has been. Patches for both vulnerabilities are available, and users who had previously patched their systems against CVE-2024-55591 are already protected against CVE-2025-24472. Workarounds such as disabling the HTTP/HTTPS administrative interface or restricting access to it by IP address are also available.
- Description
- An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
- Products
- fortiproxy, fortios
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
- Exploit added on
- Mar 18, 2025
- Exploit action due
- Apr 8, 2025
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- psirt@fortinet.com
- CWE-288
- Hype score
- Not currently trending
CISA and FBI warn of Gunra ransomware exploiting CVE-2024-55591 & CVE-2025-24472 on edge devices, followed by log wiping and double extortion. Patch perimeter assets and ship telemetry off-box. Advisory https://t.co/E2uAJb9qhq https://t.co/QC14eBVf0C
@2Workly
22 Sept 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA named the group hunting hospitals through Fortinet holes. Ask your IT company if CVE-2024-55591 and CVE-2025-24472 are patched. Then ask who owns the risk analysis. Those are two different jobs. Only one of them is usually in the MSP contract.
@jvjinfinity
20 Aug 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA, the FBI, NSA and Secret Service warn that Gunra ransomware affiliates are actively exploiting unpatched Fortinet FortiOS and FortiProxy flaws CVE-2024-55591 and CVE-2025-24472 to break into healthcare, financial and government networks worldwide. https://t.co/wtPvvZIiQp
@ShortInfoNews
15 Aug 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Gunra ransomware gang launched formal RaaS platform in January 2026 and is actively recruiting penetration testers and ethical hackers as initial access brokers for enterprise network access. US, South Korea agencies warn the group exploits CVE-2024-55591 and CVE-2025-24472
@Milwyn1
14 Aug 2026
82 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Campaña de Gunra ataca dispositivos Fortinet explotando CVE-2024-55591 y CVE-2025-24472 para evadir MFA, elevar privilegios y acceder a redes empresariales. Mas información: https://t.co/vloCGRsoWC #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/D2pZ
@EcuCERT_EC
14 Aug 2026
190 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Gunra ransomware, a Conti-based RaaS also operating as "Golden Community," is exploiting CVE-2024-55591 and CVE-2025-24472 in FortiOS/FortiProxy to hit government and critical infrastructure. #DFIR_Radar https://t.co/WBeTSTKvdr
@DFIR_Radar
12 Aug 2026
128 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Gunra ransomware actors exploited CVE-2024-55591 and CVE-2025-24472 to bypass MFA on Fortinet appliances, then compromised identity infrastructure for lateral movement. Runtime segmentation helps contain post-compromise activity when perimeter defenses fail. #ZeroTrust 🔗 Full
@aviatrixtrc
12 Aug 2026
79 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Fortinet nigdy nie zawodzi… 😅 🔴 CVE-2024-55591 — 9.8 CRITICAL 🟠 CVE-2025-24472 — 8.1 HIGH Podatności w FortiOS/FortiProxy są wykorzystywane w atakach. Warto sprawdzić wersję i aktualizacje. #Fortinet #FortiGate #CVE #CyberSecurity https://t.co/nQESAuEON8
@marekitlab
12 Aug 2026
163 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
2 Quotes
Gunra ransomware exploited critical Fortinet authentication bypass flaws (CVE-2024-55591, CVE-2025-24472) to escalate to super-admin privileges and move laterally across government networks. Runtime segmentation helps contain post-compromise activity when perimeter defenses fail.
@aviatrixtrc
12 Aug 2026
81 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Joint CSA: Gunra ransomware (CISA/FBI/NSA + allies). RaaS double-extortion on gov and critical infrastructure. Edge: FortiOS/FortiProxy CVE-2024-55591 / CVE-2025-24472. Patch exposed VPN/edge. Segment. Test offline immutable backups. https://t.co/xVWEqWnejC
@snypet86
12 Aug 2026
76 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
US, South Korea and allied agencies warn: Gunra ransomware is breaching critical infrastructure via Fortinet (CVE-2025-24472) and Schneider Electric (CVE-2024-5559) edge flaws, then defeating MFA at the VDI portal. Patch your edge. #ransomware #Fortinet
@JNitterauer
11 Aug 2026
191 Impressions
1 Retweet
2 Likes
1 Bookmark
0 Replies
0 Quotes
Gunra Linux ransomware bakes in weak key derivation that lets anyone with a sample pull the full Salsa20 or ChaCha20 key in seconds. Access starts with CVE-2024-5559 on Schneider Electric PowerLogic P5 and CVE-2025-24472 on FortiOS 7.2.0–7.4.4 plus FortiProxy. RaaS panel hands
@SecureChap
11 Aug 2026
65 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
FortiGate admins: CISA says Gunra is exploiting CVE-2024-55591 and CVE-2025-24472 to bypass MFA and steal data. PATCH. Review admin accounts, VPN logs, and configs now. https://t.co/AiSVOb4rJB
@Techsico_IT
11 Aug 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Gunra ransomware, a Conti-derived RaaS now operating globally, exploits FortiOS/FortiProxy auth bypasses and VPN default creds to hit healthcare, government, critical manufacturing and more across six regions. Key findings: - Initial access via CVE-2024-55591 and CVE-2025-24472
@DFIR_Radar
11 Aug 2026
206 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Gunra ransomware, built on leaked Conti source code, exploits FortiOS auth-bypass flaws CVE-2024-55591 and CVE-2025-24472 to plant superuser accounts before deploying ChaCha20+RSA-4096 encryption and appending .ENCRT. #DFIR_Radar https://t.co/98DUE3D73L
@DFIR_Radar
11 Aug 2026
123 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 CVE-2025-24472 — now actively exploited in the wild (CISA KEV). An Authentication Bypass Using an Alternat… Risk 51/100 · EPSS 3% · CVSS 8.1. Patch or mitigate now — attackers are already using it. https://t.co/81Q7LdzuJA #KEV #CVE #Fortinet #AuthBypass #ActivelyE
@BytesNora
8 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SuperBlack exploits CVE-2024-55591 and CVE-2025-24472 in Fortinet systems. AI ShieldNet uses behavioral AI to detect and stop zero-day attacks like this. Website: https://t.co/eeFYunNtwv #Cybersecurity #AIShieldNet #prosfinity https://t.co/Du0dl8F8rR
@prosfinity
10 Jun 2025
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Fortinetの脆弱性(CVE-2024-55591,CVE-2025-24472)を狙うサイバー攻撃が国内でも発生-JPCERTが警告 #セキュリティ対策Lab #セキュリティ #Security https://t.co/K2LlhH44nA
@securityLab_jp
9 May 2025
68 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
Hey, did you hear? Hackers are getting SUPER-ADMIN access to Fortinet firewalls using CVE-2025-24472 & deploying "SuperBlack" ransomware. Patch ASAP! #cybersecurity https://t.co/7aQ6CFwzYs
@storagetechnews
4 Apr 2025
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2025-24472
@transilienceai
3 Apr 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2025-24472
@transilienceai
31 Mar 2025
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2025-24472
@transilienceai
27 Mar 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Fortinet has patched critical vulnerabilities (NCSC-2025-0082) in FortiOS, FortiProxy, FortiPAM, FortiSRA, and FortiWeb. Exploited in ransomware attacks, this flaw allows unauthorized code execution. Patch now! #CVE-2024-55591 #CVE-2025-24472 https://t.co/tPrTnAvPap
@RedTeamNewsBlog
24 Mar 2025
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2025-24472
@transilienceai
21 Mar 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
FortiOS, FotiProxyの脆弱性の悪用が確認されているとのこと。 CVE-2025-24472 CVE-2024-55591 Fortinet Vulnerability Exploited in Ransomware Attack, CISA Warns - Infosecurity Magazine https://t.co/w3vcJozVFT
@ntsuji
21 Mar 2025
6448 Impressions
30 Retweets
69 Likes
18 Bookmarks
2 Replies
1 Quote
Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2025-24472 #Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability https://t.co/F6TsuBLDkl
@ScyScan
20 Mar 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Threat Alert: Fortinet CVE-2025-24472 Ransomware Exploitation 📅 Date: 2025-03-19 📌 Attribution: Mora_001 (potential ties to LockBit operations) 📝 Summary: A critical authentication bypass vulnerability (CVE-2025-24472) in Fortinet's FortiOS and FortiProxy technologies has…
@syedaquib77
20 Mar 2025
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2025-24472
@transilienceai
20 Mar 2025
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔴 FortiOS, Authentication Bypass, #CVE-2025-24472 (Critical) https://t.co/B3nCMGjLX5
@dailycve
19 Mar 2025
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Security Alert: CISA has issued a critical warning about a major vulnerability (CVE-2025-24472) in Fortinet’s FortiOS and FortiProxy systems. Remote attackers can exploit this flaw to gain super-admin access. 🔗 Read more: https://t.co/pJkREGY1By https://t.co/DZUfXOc8GU
@Hosainfosec
19 Mar 2025
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA warns: Fortinet FortiOS auth bypass (CVE-2025-24472) exploited in the wild. Patches out, but why bother? With WEBOUNCER, no patching, no updates—just instant protection. #Cybersecurity #WEBOUNCER #impenetrable https://t.co/PZKJp781A8 via @The_Cyber_News
@BrainLabVisions
19 Mar 2025
58 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
1 Quote
Ransomware Alert! Fortinet Under Siege: New ransomware gang SuperBlack exploits CVE-2024-55591 & CVE-2025-24472! CVE-2024-55591 – An Authentication bypass vulnerability affecting Fortinet's FortiOS and FortiProxy products. This flaw allows remote attackers to gain super-adm
@Loginsoft_Inc
19 Mar 2025
79 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が、既知の悪用された脆弱性カタログに、FortiOS/FortiProxyの認証回避CVE-2025-24472とGitHub Action tj-actions/changed-filesの悪性コードCVE-2025-30066を追加。対応期限は通常の4/8。Fortiはランサムウェア悪用済。 https://t.co/JQnPJmC90H
@__kokumoto
18 Mar 2025
1240 Impressions
4 Retweets
16 Likes
2 Bookmarks
1 Reply
0 Quotes
🛡️ We added vulnerabilities for Fortinet FortiOS & FortiProxy, CVE-2025-24472, and GitHub, CVE-2025-30066, to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/bJOgGeWmb8 & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec htt
@CISACyber
18 Mar 2025
11534 Impressions
58 Retweets
111 Likes
17 Bookmarks
5 Replies
4 Quotes
🚨 Hackers linked to LockBit are exploiting Fortinet firewall vulnerabilities (CVE-2024-55591 & CVE-2025-24472) to deploy the SuperBlack ransomware. 🔹 Data is exfiltrated before encryption 🔹 Strong ties to LockBit 3.0 ransomware 🔹 Unpatched orgs remain at risk 📌 Patch NOW
@the_aryanmittal
17 Mar 2025
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New ransomware group Mora_001 is exploiting Fortinet vulnerabilities (CVE-2024-55591, CVE-2025-24472), linked to LockBit. Affected devices may face threats if not patched. 🚨 #Fortinet #Ransomware #USA link: https://t.co/ddxsXkSqYa https://t.co/Sbhk3dsM1c
@TweetThreatNews
17 Mar 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
SuperBlack ransomware exploits Fortinet auth bypass flaws. The two vulnerabilities, both authentication bypasses, are CVE-2024-55591 and CVE-2025-24472, which Fortinet disclosed in January and February. https://t.co/D4e54UyCDn https://t.co/xjXCWZmSBr
@riskigy
16 Mar 2025
74 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cyber Alert : "SuperBlack ransomware is crashing the party, sneaking through Fortinet firewall holes (CVE-2024-55591, CVE-2025-24472)! A sneaky Russian hacker’s behind it, turning cyber chaos up to 11. Patch those systems fast—don’t let this villain steal the show!" #cybercrime
@MohamedMar66543
16 Mar 2025
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Threat Alert: Recent Fortinet Vulnerabilities Exploited in 'SuperBlack' Ransomware Attacks CVE-2024-55591 CVE-2025-24472 CVE-2025-2447 Severity: 🔴 High Maturity: 💥 Mainstream Learn more: https://t.co/sg0tFeoYVO #CyberSecurity #ThreatIntel #InfoSec
@fletch_ai
15 Mar 2025
85 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
⚠️ Vulnerability Alert: Authentication Bypass Vulnerabilities in Fortinet Firewalls 📅 Timeline: Disclosure: 2024-01-14, Patch: 2025-01-21 📌 Attribution: 🆔cveId: CVE-2024-55591, CVE-2025-24472 📊baseScore: 📏cvssMetrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H… https:
@syedaquib77
15 Mar 2025
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-55591 & CVE-2025-24472: Fortinet’s Double Vulnerability Nightmare https://t.co/vI63gkrOHW
@Dinosn
15 Mar 2025
5915 Impressions
39 Retweets
104 Likes
34 Bookmarks
0 Replies
1 Quote
CVE-2024-55591 & CVE-2025-24472: Fortinet's Double Vulnerability Nightmare Forescout researchers have identified a new ransomware group, dubbed Mora_001, exploiting two critical vulnerabilities in Fortinet products to gain unauthorized access to firewalls https://t.co/wwPp7i
@Daily_CyberSec
15 Mar 2025
924 Impressions
4 Retweets
14 Likes
6 Bookmarks
0 Replies
1 Quote
SuperBlack Ransomware Targets Fortinet Flaws Hackers exploit Fortinet CVE-2024-55591 & CVE-2025-24472 to gain super_admin access, steal data & deploy SuperBlack ransomware 🛑 Linked to LockBit, it erases forensic traces with WipeBlack! Patch now!⚠️ https://t.co/q8dvOPU
@dCypherIO
14 Mar 2025
21 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🗞️ SuperBlack Ransomware Exploits Fortinet Auth Bypass Flaws in Targeted Attacks The new SuperBlack ransomware is exploiting Fortinet auth bypass flaws (CVE-2025-24472) to hit unpatched firewalls, with Forescout linking it to LockBit tactics. Over 23K vulnerable devices remain…
@gossy_84
14 Mar 2025
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 SuperBlack ransomware is exploiting Fortinet vulnerabilities! 📌 CVE-2024-55591 & CVE-2025-24472 used for initial access 📌 Double extortion + custom wiper WipeBlack 📌 Uses LockBit’s leaked builder Patch your systems! Breaking news from the world &… https://t.co/ZF7G3
@godeepweb
14 Mar 2025
37 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Recent Fortinet Vulnerabilities Exploited in ‘SuperBlack’ Ransomware Attacks The newly discovered SuperBlack ransomware has been exploiting two vulnerabilities CVE-2024-55591 and CVE-2025-24472 in Fortinet firewalls. https://t.co/1TlLQtZmcC https://t.co/Pf5olgk4t6
@persistsec
14 Mar 2025
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
According to Forescout, SuperBlack ransomware is exploiting CVE-2024-55591 and CVE-2025-24472, which target FortiGate 7.0.X management interfaces patched in Jan 2025. My latest investigation found over 30K vulnerable servers worldwide (Mgmt interface exposed, no patch applied). h
@nekono_naha
14 Mar 2025
1333 Impressions
4 Retweets
9 Likes
4 Bookmarks
0 Replies
0 Quotes
2025年1月に修正されたFortiGate7.0.X系の管理画面を対象としたCVE-2024-55591、CVE-2025-24472を悪用したSuperBlackランサム攻撃をForescout社が報告。調査した所、本日時点でもグローバルで23K台、国内1K台超の脆弱サーバを発見。なお、管理画面閉鎖、パッチ適用済み機器でも以下のような極めて面倒… https://t.co/FYC5CH9Lqq https://t.co/kpJ4Cr5M7f
@nekono_naha
14 Mar 2025
3008 Impressions
8 Retweets
39 Likes
18 Bookmarks
0 Replies
1 Quote
A ransomware group, Mora_001, exploits Fortinet vulnerabilities CVE-2024-55591 and CVE-2025-24472 to deploy SuperBlack ransomware, with the latter confirmed exploited in attacks since February 2025, despite prior reassurances from Fortinet. #Security https://t.co/ARD6Z4X3bb
@Strivehawk
13 Mar 2025
65 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
#threatreport #LowCompleteness Flash Notice: CVE-2025-24472 Actively Exploited - Patch and Manage | 03-03-2025 Source: https://t.co/PsbNnmQd6Y Key details below ↓ 🎯Victims: Fortinet 🔓CVEs: CVE-2024-55591 \[[Vulners](https://t.co/cNWxPVNtLL)] - CVSS V3.1: *9.8*, -… https:/
@rst_cloud
3 Mar 2025
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1B14CD59-F557-48A0-8458-BECD3AD7DB3A",
"versionEndExcluding": "7.0.20",
"versionStartIncluding": "7.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EDC18768-0891-465E-9900-3DF5D22A5CB3",
"versionEndExcluding": "7.2.13",
"versionStartIncluding": "7.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BD357034-B2FD-4C2E-97FE-2C54D686D885",
"versionEndExcluding": "7.0.17",
"versionStartIncluding": "7.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]