An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanCISA ADP Vulnrichment affects Fortinet/FortiOS (generic), Fortinet/FortiProxy (generic). Severity is critical. This vulnerability is known to be exploited in the wild. An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
AI coding agents often install or upgrade packages automatically in generic. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Fortinet/FortiOSgeneric | 7.0.0 | Not reported |
| Fortinet/FortiProxy |
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanCISA ADP Vulnrichment affects Fortinet/FortiOS (generic), Fortinet/FortiProxy (generic). Severity is critical. This vulnerability is known to be exploited in the wild. An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
AI coding agents often install or upgrade packages automatically in generic. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Fortinet/FortiOSgeneric | 7.0.0 | Not reported |
| Fortinet/FortiProxy |
| 7.2.0 || 7.0.0 |
| Not reported |
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| 7.2.0 || 7.0.0 |
| Not reported |
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard