Use After Free Vulnerability in Fortinet FortiManager and FortiAnalyzer

CVE-2021-32589

7.7HIGH

Key Information

Vendor
Fortinet
Status
Fortimanager
Fortianalyzer
Vendor
CVE Published:
19 December 2024

Summary

CVE-2021-32589 is a high-severity vulnerability discovered in Fortinet's FortiManager and FortiAnalyzer products. This vulnerability arises from a use after free scenario, which could allow an attacker to execute unauthorized code or commands on the affected systems. Exploiting this flaw could lead to significant security breaches, making it critical for users to apply recommended patches and updates immediately to protect their infrastructure. For more details, refer to the official Fortinet security advisory.

Affected Version(s)

FortiManager = 7.0.0

FortiManager <= 6.4.5

FortiManager <= 6.2.7

Refferences

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.