LiveActive security incident?Get immediate response
CVE Record

CVE-2024-55599: An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, ver...

An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices.

MediumCVSS 4.9Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Affected Fortinet gateways may fail to enforce DNS filtering for traffic from Apple devices. An unauthenticated remote user could reach destinations that policy should block. The issue affects filtering integrity, not confidentiality or service availability, and is rated CVSS 4.9.

Executive priority

Schedule prompt remediation through normal vulnerability management, accelerating systems where DNS filtering protects regulated, restricted, or high-risk users. This is not presented as an emergency compromise event, but affected controls may provide less protection than leadership expects.

Technical view

CVE-2024-55599 is a CWE-358 security-check implementation flaw in specified FortiOS and FortiProxy releases. It is remotely reachable with low complexity, requires no privileges or user interaction, and can bypass DNS filtering via Apple devices. The CVSS vector indicates low integrity impact with no confidentiality or availability impact.

Likely exposure

Exposure is most relevant where affected FortiOS or FortiProxy versions enforce DNS-filter policies for Apple-device traffic. The bundle lists multiple affected release branches, but configuration-specific prerequisites and the precise Apple protocol behavior are not provided.

Exploitation context

The supplied record does not establish active exploitation, and the CVE is not listed as KEV in the bundle. The weakness is remotely reachable without authentication, but evidence about public proof-of-concept availability, observed attacks, or exploitation frequency is absent.

Researcher notes

The source bundle contains some version-detail ambiguity, particularly around FortiOS 7.2 listings. Use the Fortinet advisory as the authoritative applicability source. No technical root-cause detail, indicators of compromise, workaround specifics, or confirmed exploitation evidence is supplied.

Mitigation direction

  • Inventory FortiOS and FortiProxy versions handling DNS-filtered Apple-device traffic.
  • Consult Fortinet advisory FG-IR-24-053 for supported fixed releases or vendor-approved mitigations.
  • Prioritize upgrades where DNS filtering is a required security or compliance control.
  • Apply compensating DNS enforcement outside the affected appliance if immediate remediation is unavailable.

Validation and detection

  • Confirm each appliance product, firmware version, and DNS-filter configuration against Fortinet's advisory.
  • Identify Apple-device networks whose DNS traffic traverses affected appliances.
  • Review logs for unexpectedly permitted DNS requests from Apple clients; absence does not prove non-exploitation.
  • After remediation, safely verify that policy-blocked destinations remain blocked from managed Apple devices.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-358: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2024-55599 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
4.9 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:X/RC:X

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
2ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
4.9CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:X/RC:X3.91.4fortinet

Vulnerability scoring details

Base CVSS 3.1 score

4.9Medium
CVSS 3.1 vector shape for CVE-2024-55599Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:X/RC:X

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
siemens-SADPADP container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
FortinetFortiOS7.6.0, 7.4.0, 7.2.0, 7.0.0, 6.4.0unaffected
FortinetFortiProxy7.6.0, 7.4.0, 7.2.0, 7.0.0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-358 · source CWE mapping

Improperly Implemented Security Check for Standard

Improperly Implemented Security Check for Standard represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.