Impact
The vulnerability is a heap-based buffer overflow in the Fireware OS IKED process that allows an authenticated administrator to crash the IKE daemon by saving a specially crafted configuration file. This results in a denial of service, interrupting essential authentication services.
Affected Systems
WatchGuard Fireware OS is impacted. Any version older than Fireware OS 2026.2.1, 12.12.1, 12.11.9, or 12.5.18 is vulnerable, regardless of the specific minor revision.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The attack requires administrative credentials and a crafted configuration, limiting the threat to trusted users or compromised administrative accounts. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Overall risk is moderate, with direct impact on service availability rather than confidentiality or integrity.
OpenCVE Enrichment