Impact
An integer underflow in the iked process of WatchGuard Fireware OS allows an attacker to send crafted packets that interrupt VPN handling, causing the firewall to become unresponsive. The flaw can be triggered without authentication and results in a denial of service that affects the availability of the VPN service and potentially the entire network segmentation function of the device.
Affected Systems
The vulnerability exists in all supported releases of WatchGuard Fireware OS up to the officially released updates. Devices running versions before Fireware OS 2026.2.2, 12.12.2, or 12.5.20 are susceptible. Any organization using WatchGuard Fireware OS for VPN connectivity should verify that its firmware matches one of the patched releases.
Risk and Exploitability
The CVSS base score of 8.7 indicates high exploitation potential, though the EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog. Because the attack can be performed remotely without authentication, the risk to network availability is significant. Patch application is the primary mitigation to remove the Integer Underflow and associated Out‑of‑Bounds Write weaknesses identified as CWE‑191 and CWE‑787.
OpenCVE Enrichment