Fireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Service (DoS)
Summary #
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.
Impact: A remote unauthenticated attacker who completes an IKEv2 SA_INIT exchange can send a crafted encrypted INFORMATIONAL message containing a malformed DELETE payload to cause iked to read up to approximately 196 KiB beyond the end of a heap allocation. This reliably crashes the iked process, resulting in a denial-of-service condition for IKEv2 VPN services, and could potentially expose adjacent heap memory (e.g., other IKE SA key material or certificate data) to an attacker under favorable heap layout conditions.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Fireware OS | ||
| Default | >= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2 | >= 2026.2.2, >= 12.12.2 |
| T15/T35 | >= 12.0, < 12.5.20 | >= 12.5.20 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Solution #
References #
Credits #
- Discovered Internally by WatchGuard AI Security Researchfinder