A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.

This vulnerability affects Fireware OS 12.0 up to and including 12.11.4 and 2025.1 up to and including 2025.1.2.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 04 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
Description A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. This vulnerability affects Fireware OS 12.0 up to and including 12.11.4 and 2025.1 up to and including 2025.1.2.
Title WatchGuard Firebox iked Memory Corruption Vulnerability
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-763
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2025-12-05T15:44:31.064Z

Reserved: 2025-10-16T06:58:57.085Z

Link: CVE-2025-11838

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-04T22:15:46.610

Modified: 2025-12-04T22:15:46.610

Link: CVE-2025-11838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses