CISA description
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Fortinet · FortiOS and FortiProxy
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Vulnerability data triggers these controls during assessment and continuous monitoring.