ZeroHour

CVE-2026-19314

large

Unauthenticated DoS in WatchGuard Fireware OS iked VPN daemon

CVSS 4.0
8.7 high
EPSS
<1%p25
Published
()
Modified
AI analysis

WatchGuard Fireware OS contains an integer underflow (CWE-191) in the iked process, the daemon that handles IKE key negotiation for VPN tunnels, which can lead to an out-of-bounds write (CWE-787). A remote, unauthenticated attacker can trigger the flaw by sending specially crafted network traffic to a Firebox appliance's IKE/VPN service. Successful exploitation causes a Denial of Service condition in VPN processing; the CVSS 4.0 score of 8.7 reflects high availability impact with no confidentiality or integrity impact. Organizations running WatchGuard Firebox appliances with Fireware OS and an IKE-based (IPsec) VPN service reachable by untrusted networks are potentially affected. Exploitation has not been observed: no public PoC is known, the CVE is not in CISA KEV, and EPSS estimates only a ~0.3% probability of exploitation within 30 days (25th percentile).

What to do: Check whether IKE (UDP 500/4500) is exposed on your Firebox's external interfaces and apply the patched Fireware OS build cited in WatchGuard's advisory for this CVE once available, as no specific version numbers are listed in this data. As an interim mitigation, restrict inbound IKE traffic to known VPN peer addresses with ACLs and disable any unused IKE services. If VPN processing is disrupted, a restart of the iked service (or the appliance) typically restores it, but patching is required to remove the flaw.

Affected
WatchGuard Fireware OS (iked process, as deployed on WatchGuard Firebox appliances)
Estimated exposure
largetens of thousands of internet-exposed Firebox devices (of an installed base likely in the hundreds of thousands) — WatchGuard Firebox firewalls are widely deployed in SMB and branch-office environments with an installed base in the hundreds of thousands of devices, and public internet scans (Shodan/Censys) have historically shown tens of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An integer underflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.

Weakness
CWE-191, CWE-787
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.