Impact
This vulnerability is a double‑free flaw in the iked process of Fireware OS. The flaw allows an attacker to send crafted packets that cause a memory corruption, leading to a crash of the VPN service and a denial of service condition. The weakness is categorized as CWE‑415 (Double Free) and CWE‑416 (Use After Free) and would make the device unable to handle VPN traffic until it is restarted or the firmware is fixed.
Affected Systems
The affected vendor is WatchGuard. All deployments running the Fireware OS firmware that do not have the latest releases listed in the vendor advisory—specifically the 2026‑2.2, 12‑12.2 or 12‑5.20 patch releases—are vulnerable. The problem resides in the iked VPN daemon and does not require privilege escalation beyond network access to the device.
Risk and Exploitability
The CVSS score for this issue is 8.7 and the EPSS score is not available, indicating a high severity but lacking a current likelihood estimate. The vulnerability is not yet listed in the CISA KEV catalog, but the attack vector is remote, unauthenticated, and possible over the network. An attacker could trigger the DoS by sending malicious packets to the iked service without authentication, potentially disrupting VPN service for all users connected to the affected device.
OpenCVE Enrichment