Memory Corruption Vulnerability in WatchGuard Fireware OS
CVE-2025-11838
8.7HIGH
What is CVE-2025-11838?
A memory corruption flaw exists in WatchGuard Fireware OS that enables unauthenticated attackers to exploit the Mobile User VPN and Branch Office VPN functionality utilizing IKEv2. When the VPN is set up with a dynamic gateway peer, this vulnerability can lead to a Denial of Service (DoS) condition, disrupting service availability. The issue affects multiple versions of Fireware OS, including those ranging from 12.0 to 12.11.4 and 2025.1 to 2025.1.2.
Affected Version(s)
Fireware OS 12.0 <= 12.11.4
Fireware OS 2025.1 <= 2025.1.2
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
McCaulay Hudson (@_McCaulay) of watchTowr
