CVE-2024-5974

Firebox Authenticated Buffer Overflow Vulnerability

High 8.6 CVSS v4.0 › Published 2024-07-09Updated 2026-08-07

Summary #

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10.3.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 11.9.4, < 12.10.4>= 12.10.4
T15/T35 >= 12.0, < 12.5.12+701324>= 12.5.12+701324

Weakness Type and Impact #

  • CWECWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
  • CAPECCAPEC-242Code Injection

Solution #

Fireware OS 12.10.4, Fireware OS 12.5.12+701324

References #

Credits #

  • Discovered internally by WatchGuardfinder