Description
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Published: 2026-08-27
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WatchGuard Fireware OS contains an out‑of‑bounds read in the iked daemon that causes the process to crash when it receives specially crafted VPN packets. The flaw is triggered by an unauthenticated network attacker and results in a denial of service that disrupts VPN processing and connectivity for all users of the affected device.

Affected Systems

The vulnerability applies to the WatchGuard Fireware OS product line, specifically versions addressed in the vendor’s fix: 2026.2.2, 12.12.2, and 12.5.20.

Risk and Exploitability

With a CVSS score of 8.7 the flaw poses a high severity risk. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. The attack vector is remote and does not require authentication, so any attacker with network access to the VPN endpoint could send the truncated packets and force a service halt.

Generated by OpenCVE AI on August 28, 2026 at 05:36 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20


OpenCVE Recommended Actions

  • Update the device to the vendor‑supplied release 2026.2.2, 12.12.2, or 12.5.20 to eliminate the vulnerable iked process.
  • If an immediate upgrade is not possible, disable or tightly restrict outbound VPN traffic at the firewall to prevent the crafted packets from reaching the iked service while a patch is deployed.
  • Continuously monitor VPN logs for unusual packet patterns or critical errors that may indicate an attempted exploitation, and apply additional logging or alerts as needed.

Generated by OpenCVE AI on August 28, 2026 at 05:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Title Fireware OS Pre-Authentication Out-of-Bounds Read in iked Allows Denial of Service (DoS)
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-125
CWE-191
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:24:33.131Z

Reserved: 2026-08-07T20:06:02.743Z

Link: CVE-2026-19317

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:20.947

Modified: 2026-08-28T02:16:20.947

Link: CVE-2026-19317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:45:04Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-191

    Integer Underflow (Wrap or Wraparound)