Description
A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.

This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2
Published: 2026-07-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A null pointer dereference exists in the IKEv2 (iked) process of WatchGuard Fireware OS, enabling a remote unauthenticated attacker to send specially crafted IKEv2 messages that crash the VPN daemon and trigger a denial‑of‑service condition. The flaw is a classic CWE‑476 null pointer dereference and impacts only the VPN service, interrupting connectivity for users.

Affected Systems

The vulnerability affects WatchGuard Fireware OS versions 11.10.2 through 11.12.4_Update1, 12.0 through 12.12, and 2025.1 through 2026.2. Both the Mobile User VPN and the Branch Office VPN configurations that use dynamic gateway peers are susceptible.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity, while the EPSS score of less than 1% indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV, meaning no confirmed exploits have been observed. Attackers need only send untrusted IKEv2 traffic to a vulnerable VPN endpoint, no authentication is required, making the attack vector remote and straightforward.

Generated by OpenCVE AI on July 21, 2026 at 10:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update that addresses the null pointer dereference in the IKEv2 process.
  • If patching is delayed, restrict inbound IKEv2 traffic to known, trusted peers or temporarily disable IKEv2 on the vulnerable VPN configuration.
  • Deploy network monitoring or intrusion detection rules to flag abnormal IKEv2 traffic patterns that may indicate exploitation attempts.

Generated by OpenCVE AI on July 21, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2
Title Null Pointer Dereference in WatchGuard Fireware OS iked Process
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-476
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.10.2
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-06T14:54:50.318Z

Reserved: 2026-06-23T18:29:23.985Z

Link: CVE-2026-13084

cve-icon Vulnrichment

Updated: 2026-07-06T14:54:44.629Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses