CVE-2021-32589: Use After Free
A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiAnalyzer version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.3.11, version 5.2.10 to 5.2.4 fgfmsd daemon may allow a remote, non-authenticated attacker to execute unauthorized code as root via sending a specifically crafted request to the fgfm port of the targeted device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32589?
CVE-2021-32589 has been assigned a high severity rating due to potential exploitation leading to unauthorized access.
How do I fix CVE-2021-32589?
To fix CVE-2021-32589, upgrade FortiManager and FortiAnalyzer to versions that are not vulnerable, specifically versions greater than 6.4.6, 6.2.8, 6.0.11, 5.6.11, 5.4.8, 5.2.11, and 5.0.13.
Which versions are affected by CVE-2021-32589?
CVE-2021-32589 affects FortiManager versions 7.0.0, 6.4.5 and below, and FortiAnalyzer versions 7.0.0, 6.4.5 and below.
What kind of vulnerability is CVE-2021-32589 classified as?
CVE-2021-32589 is classified as a Use After Free vulnerability (CWE-416) which can lead to serious security issues.
Is there a known exploit for CVE-2021-32589?
While details regarding active exploits for CVE-2021-32589 are not publicly detailed, the high severity rating suggests potential for exploitation.