FortiWLC - Denial of service due to dereferencing of undefined pointer

Summary

An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command.

Affected Products

At least
FortiWLC version 8.0.6
FortiWLC version 8.1.2 through 8.1.3
FortiWLC version 8.2.4 through 8.2.7
FortiWLC version 8.3.0 through 8.3.3
FortiWLC version 8.4.0 through 8.4.8
FortiWLC version 8.5.0 through 8.5.5
FortiWLC version 8.6.0 through 8.6.2

Solutions

Please upgrade to FortiWLC version 8.6.3 or above.

Acknowledgement

Fortinet is pleased to thank a FortiWLC customer for bringing this issue to our attention.

Timeline

2022-04-05: Initial publication