Impact
An out‑of‑bounds write flaw exists in the WatchGuard Fireware OS ikestubd service. The vulnerability is triggered by a specially crafted request sent to the Management Web UI. The memory corruption allows an authenticated privileged user to execute arbitrary code on the device with the privileges of the ikestubd process. This can compromise confidentiality, integrity, and availability of the system. The weakness is classified as CWE‑787.
Affected Systems
Affected systems are not specifically enumerated in the CVE data; the vulnerability applies to WatchGuard Fireware OS components that include the ikestubd process and expose the Management Web UI.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score of less than 1% suggests a low but measurable likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, meaning no public exploits are known. Exploitation requires an authenticated privileged user with access to the Management Web UI; unauthenticated remote attack is not possible.
OpenCVE Enrichment