Rewterz
Rewterz Threat Alert – AZORult Active-IOCs
July 19, 2021
Rewterz
Rewterz Threat Advisory – ICS: Mitsubishi Electric MELSEC-F Series
July 21, 2021

Rewterz Threat Advisory – FortiManager & FortiAnalyzer – Use after free vulnerability

Severity

High

Analysis Summary

CVE-2021-32589

A Use After Free vulnerability in FortiManager and FortiAnalyzer fgfmsd daemon may allow a remote, non-authenticated attacker to execute unauthorized code as root via sending a specifically crafted request to the fgfm port of the targeted device.

Impact

  • Remote code execution

Affected Vendors

Fortinet

Affected Products

  • FortiManager versions 5.6.10 and below.

Remediation

Refer to vendor advisory for the complete list of affected products and their respective patches.

https://www.fortiguard.com/psirt/FG-IR-21-067