Executive brief
WatchGuard Fireware OS powers firewalls and VPN gateways that protect corporate networks and enable remote workers to connect securely. A memory corruption flaw in the IKEv2 VPN implementation allows unauthenticated remote attackers to crash the VPN service, disrupting access for mobile and branch office users. No patches are available for affected versions.
Technical details
This vulnerability is a memory corruption issue (CWE-763: release of invalid pointer or reference) in the iked (IKE daemon) component that handles Mobile User VPN with IKEv2 and Branch Office VPN with IKEv2 when configured with a dynamic gateway peer. The flaw is reachable over the network without authentication. An attacker can send crafted IKE packets to trigger the memory corruption and cause a denial of service by crashing the iked daemon. The vulnerability affects Fireware OS versions 2025.1 through 2025.1.3 and 12.6.1 through 12.11.5, with fixes available in versions 2025.1.3 and 12.11.5.
Affected products
- WatchGuard Fireware OS 2025.1 to 2025.1.3, 12.6.1 to 12.11.5
Timeline
- 2025-12-04: disclosed
- 2025-12-04: patched: Fixes available in Fireware OS 2025.1.3 and 12.11.5