FortiWLC - Access of Uninitialized Pointer vulnerability


An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command.

Affected Products

At least
FortiWLC version 8.0.6
FortiWLC version 8.1.2 through 8.1.3
FortiWLC version 8.2.4 through 8.2.7
FortiWLC version 8.3.0 through 8.3.3
FortiWLC version 8.4.0 through 8.4.8
FortiWLC version 8.5.0 through 8.5.5
FortiWLC version 8.6.0 through 8.6.2


Please upgrade to FortiWLC version 8.6.3 or above.


Fortinet is pleased to thank a FortiWLC customer for bringing this issue to our attention.