Improper Security Check in FortiOS and FortiProxy Affects Apple Devices
CVE-2024-55599

4.9MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
8 July 2025

What is CVE-2024-55599?

A vulnerability in FortiOS and FortiProxy, characterized by an improperly implemented security check, may enable a remote unauthenticated user to bypass DNS filtering specifically on Apple devices. The affected versions include FortiOS 7.6.0, 7.4.7 and below, as well as all versions of 7.0 and 6.4. Similarly, FortiProxy versions affected are 7.6.1 and below, 7.4.8 and below, all versions of 7.2, and all versions of 7.0. This security flaw poses a risk, allowing unauthorized access to potentially sensitive information. For further details, refer to Fortinet's advisory.

Affected Version(s)

FortiOS 7.6.0

FortiOS 7.4.0 <= 7.4.7

FortiOS 7.2.0 <= 7.2.10

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-55599 : Improper Security Check in FortiOS and FortiProxy Affects Apple Devices