CVE-2021-32589

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Dec 19, 2024
CWE ID 416

Summary

CVE-2021-32589 is a Use After Free (UAF) vulnerability affecting multiple FortiManager and FortiAnalyzer versions. Specifically, the issue lies in the fgfm daemon of these products. A remote, non-authenticated attacker can exploit this vulnerability by sending a specially crafted request to the fgfm port. Successful exploitation allows the attacker to execute unauthorized code with root privileges. Affected versions include FortiManager 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.10 and below, 5.6.10 and below, 5.4.7 and below, 5.2.10 and below, and FortiAnalyzer 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.10 and below, 5.6.10 and below, 5.4.7 and below, 5.3.11, and 5.2.10 to 5.2.4. Upgrading to the latest patched versions is recommended to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • FortiManager
  • FortiAnalyzer

Affected Vendors

  • Fortinet