FortiWLC - Denial of service due to dereferencing of undefined pointer
Summary
An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command.
Affected Products
At least
FortiWLC version 8.0.6
FortiWLC version 8.1.2 through 8.1.3
FortiWLC version 8.2.4 through 8.2.7
FortiWLC version 8.3.0 through 8.3.3
FortiWLC version 8.4.0 through 8.4.8
FortiWLC version 8.5.0 through 8.5.5
FortiWLC version 8.6.0 through 8.6.2
Solutions
Please upgrade to FortiWLC version 8.6.3 or above.
Acknowledgement
Fortinet is pleased to thank a FortiWLC customer for bringing this issue to our attention.Timeline
2022-04-05: Initial publication