CVE-2021-32589 Information

Description

A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0 version 6.4.5 and below version 6.2.7 and below version 6.0.10 and below version 5.6.10 and below version 5.4.7 and below version 5.2.10 and below version 5.0.12 and below and FortiAnalyzer version 7.0.0 version 6.4.5 and below version 6.2.7 and below version 6.0.10 and below version 5.6.10 and below version 5.4.7 and below version 5.3.11 version 5.2.10 to 5.2.4 fgfmsd daemon may allow a remote non-authenticated attacker to execute unauthorized code as root via sending a specifically crafted request to the fgfm port of the targeted device.

Reference

https://fortiguard.fortinet.com/psirt/FG-IR-21-067

Share on: