Description
An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Published: 2026-08-27
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WatchGuard Fireware OS iked process contains an integer underflow flaw that allows an attacker to send specially crafted traffic and trigger a denial of service condition in VPN processing. This flaw results in the iked service becoming unresponsive or crashing, effectively disrupting VPN connectivity for all users connected to the affected device. The underlying weakness involves integer underflow and an out‑of‑bounds write, which can be mapped to CWE‑191 and CWE‑787. As a result, the confidentiality and integrity of data are not directly compromised, but the availability of VPN services is severely impacted, potentially leaving the network exposed to further network‑level disruptions or congestion.

Affected Systems

Affected systems are devices running WatchGuard Fireware OS. Versions prior to the patched releases 2026.2.2, 12.12.2, or 12.5.20 are vulnerable. The fix is provided by the corresponding firmware updates. All deployments that use the iked VPN service and are running any version of Fireware OS older than those releases should be considered at risk.

Risk and Exploitability

Risk assessment: The CVSS score of 8.7 classifies this vulnerability as high severity. The EPSS score is not available, but the absence of a KEV listing and the remote, unauthenticated nature of the exploit suggest that discovery may be opportunistic yet still realistic for adversaries seeking to disrupt VPN traffic. An attacker can remotely send crafted packets to the device, triggering the underflow and causing the iked process to fail, without requiring authentication. Therefore organizations should treat this as a high‑risk denial of service that can affect mission‑critical VPN connectivity.

Generated by OpenCVE AI on August 28, 2026 at 05:36 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20


OpenCVE Recommended Actions

  • Apply the latest Fireware OS firmware update addressing the integer underflow flaw (e.g., Fireware OS 2026.2.2, 12.12.2, or 12.5.20 depending on your deployment).
  • Reconfigure the firewall to allow only trusted VPN initiators or whitelist the VPN endpoints to reduce the attack surface while the device remains stable.
  • Monitor VPN traffic and the health of the iked service for indications of instability; if the service continues to recreate a DoS condition, report the issue to WatchGuard for further investigation or consider isolating the VPN functionality temporarily.

Generated by OpenCVE AI on August 28, 2026 at 05:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Title Fireware OS Integer Underflow in iked Allows Unauthenticated Denial of Service (DoS)
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-191
CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:24:33.254Z

Reserved: 2026-08-07T20:05:53.603Z

Link: CVE-2026-19314

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:20.580

Modified: 2026-08-28T02:16:20.580

Link: CVE-2026-19314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:15:03Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)

  • CWE-787

    Out-of-bounds Write