Description
A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration.
Published: 2026-08-27
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via crashed IKE daemon
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a heap-based buffer overflow in the Fireware OS IKED process that allows an authenticated administrator to crash the IKE daemon by saving a specially crafted configuration file. This results in a denial of service, interrupting essential authentication services.

Affected Systems

WatchGuard Fireware OS is impacted. Any version older than Fireware OS 2026.2.1, 12.12.1, 12.11.9, or 12.5.18 is vulnerable, regardless of the specific minor revision.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. The attack requires administrative credentials and a crafted configuration, limiting the threat to trusted users or compromised administrative accounts. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Overall risk is moderate, with direct impact on service availability rather than confidentiality or integrity.

Generated by OpenCVE AI on August 28, 2026 at 09:03 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1, Fireware OS 12.11.9, Fireware OS 12.5.18


OpenCVE Recommended Actions

  • Install the vendor‑released patches: Fireware OS 2026.2.1, 12.12.1, 12.11.9, or 12.5.18, depending on the current OS release.
  • Temporarily stop the iked daemon or disable IKE configuration changes until the update is applied.
  • Restrict privileged access to configuration tools that interact with iked so that only trusted administrators can apply changes.

Generated by OpenCVE AI on August 28, 2026 at 09:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration.
Title Fireware OS Heap-Based Buffer Overflow in iked Allows Denial of Service
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-122
CWE-1284
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-28T15:57:26.539Z

Reserved: 2026-08-27T16:29:07.182Z

Link: CVE-2026-81851

cve-icon Vulnrichment

Updated: 2026-08-28T14:33:10.264Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T00:18:22.687

Modified: 2026-08-28T20:20:14.080

Link: CVE-2026-81851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T09:15:05Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-1284

    Improper Validation of Specified Quantity in Input