CVE-2021-26093
published 2024-12-19CVE-2021-26093: An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash…
PriorityP425medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.16%
5.6th percentile
An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiwlc | — | — |
| fortinet | fortiwlc | — | — |
| fortinet | fortiwlc | — | — |
| fortinet | fortiwlc | >= 8.0.6 < 8.6.3 | 8.6.3 |
| fortinet | fortiwlc | 8.1.2 – 8.1.3 | — |
| fortinet | fortiwlc | 8.2.4 – 8.2.7 | — |
| fortinet | fortiwlc | 8.3.0 – 8.3.3 | — |
| fortinet | fortiwlc | 8.4.0 – 8.4.2 | — |
| fortinet | fortiwlc | 8.4.4 – 8.4.8 | — |
| fortinet | fortiwlc | 8.5.0 – 8.5.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a loc...
vendor_fortinet·2024-12-19·CVSS 7.3
CVE-2021-26093 [HIGH] CWE-824 An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a loc...
FG-IR-21-002: An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a loc...
An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command.
CVEs: CVE-2021-26093
CWEs: CWE-824
CVSS: 7.3 (high)
Affected products: FortiWLC
GHSA
GHSA-mx92-m8m9-32fq: An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8
ghsa_unreviewed·2024-12-19
CVE-2021-26093 [HIGH] CWE-824 GHSA-mx92-m8m9-32fq: An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8
An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-19
Published