Blog | G5 Cyber Security

A bug in Fortinet FortiManager and FortiAnalyzer allows unauthenticated hackers to run code as root

Fortinet has released security updates to address a serious bug, tracked as CVE-2021-32589, affecting FortiManager and FortiAnalyzer network management solutions. The vulnerability is a Use After Free issue that an attacker could exploit to execute arbitrary code as root. The affected products include Forti manager versions 5.4.6.0.10 and 6.2.7.0. The flaw was reported to the vendor by security expert Cyrille Chatras from the Orange group. The company also provides workaround to address the issue.”]

Source: https://securityaffairs.co/wordpress/120350/security/fortinet-fortimanager-fortianalyzer-bug.html

Exit mobile version