An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request.
The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fortios | Fortinet | 6.4.0 (including) | 7.4.9 (excluding) |
Fortios | Fortinet | 7.6.0 (including) | 7.6.4 (excluding) |