Impact
The WatchGuard Fireware OS iked process contains an integer underflow flaw that allows an attacker to send specially crafted traffic and trigger a denial of service condition in VPN processing. This flaw results in the iked service becoming unresponsive or crashing, effectively disrupting VPN connectivity for all users connected to the affected device. The underlying weakness involves integer underflow and an out‑of‑bounds write, which can be mapped to CWE‑191 and CWE‑787. As a result, the confidentiality and integrity of data are not directly compromised, but the availability of VPN services is severely impacted, potentially leaving the network exposed to further network‑level disruptions or congestion.
Affected Systems
Affected systems are devices running WatchGuard Fireware OS. Versions prior to the patched releases 2026.2.2, 12.12.2, or 12.5.20 are vulnerable. The fix is provided by the corresponding firmware updates. All deployments that use the iked VPN service and are running any version of Fireware OS older than those releases should be considered at risk.
Risk and Exploitability
Risk assessment: The CVSS score of 8.7 classifies this vulnerability as high severity. The EPSS score is not available, but the absence of a KEV listing and the remote, unauthenticated nature of the exploit suggest that discovery may be opportunistic yet still realistic for adversaries seeking to disrupt VPN traffic. An attacker can remotely send crafted packets to the device, triggering the underflow and causing the iked process to fail, without requiring authentication. Therefore organizations should treat this as a high‑risk denial of service that can affect mission‑critical VPN connectivity.
OpenCVE Enrichment