An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortios | 6.4.0 | 7.4.9 |
| fortinet / fortios | 7.6.0 | 7.6.4 |