CVE-2021-32589
Description
A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiAnalyzer version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.3.11, version 5.2.10 to 5.2.4 fgfmsd daemon may allow a remote, non-authenticated attacker to execute unauthorized code as root via sending a specifically crafted request to the fgfm port of the targeted device.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Use After Free
StableCommon Consequences
Applicable Platforms
Fortiportal by Fortinet
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
Fortianalyzer by Fortinet
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Fortianalyzer by Fortinet
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Fortimanager by Fortinet
cpe:2.3:a:fortinet:fortimanager:7.0.0:*:*:*:*:*:*:*
Fortimanager by Fortinet
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Fortimanager by Fortinet
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Fortianalyzer by Fortinet
cpe:2.3:a:fortinet:fortianalyzer:7.0.0:*:*:*:*:*:*:*
Fortianalyzer by Fortinet
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Fortianalyzer by Fortinet
cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
Fortimanager by Fortinet
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
Fortiportal by Fortinet
cpe:2.3:a:fortinet:fortiportal:*:*:*:*:*:*:*:*
Fortimanager by Fortinet
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*