QID 375744
Date Published: 2021-08-06
QID 375744: FortiManager And FortiAnalyzer Use After Free (CWE-416) vulnerability
FortiManager provides centralized policy-based provisioning, device configuration, and update management for for FortiGate, FortiWiFi, and FortiMail appliances, and FortiClient end-point security agents, plus end-to-end network monitoring and device control.
Affected Products:
FortiManager versions 5.6.10 and below.
FortiManager versions 6.0.10 and below.
FortiManager versions 6.2.7 and below.
FortiManager versions 6.4.5 and below.
FortiManager version 7.0.0.
FortiManager versions 5.4.x.
FortiAnalyzer versions 5.6.10 and below.
FortiAnalyzer versions 6.0.10 and below.
FortiAnalyzer versions 6.2.7 and below.
FortiAnalyzer versions 6.4.5 and below.
FortiAnalyzer version 7.0.0.
Detection Login(Authenticated)
QID will fire the command get system status and will match the affected version
A successful exploit could allow an attacker to execute a cross site scripting (XSS) via the Identify Provider name field.
Customers are advised to refer to FG-IR-21-067 for more information.Workaround:
Disable FortiManager features on the FortiAnalyzer unit using the command below:
config system global
set fmg-status disable --- Disabled by default.
- FG-IR-21-067 -
www.fortiguard.com/psirt/FG-IR-21-067
CVEs related to QID 375744
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FG-IR-21-067 |
|