A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. This vulnerability affects Fireware OS 12.0 up to and including 12.11.4 and 2025.1 up to and including 2025.1.2.
History

Fri, 05 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
Description A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. This vulnerability affects Fireware OS 12.0 up to and including 12.11.4 and 2025.1 up to and including 2025.1.2.
Title WatchGuard Firebox iked Memory Corruption Vulnerability
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-763
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published: 2025-12-04T21:48:10.961Z

Updated: 2025-12-05T15:44:31.064Z

Reserved: 2025-10-16T06:58:57.085Z

Link: CVE-2025-11838

cve-icon Vulnrichment

Updated: 2025-12-05T15:44:27.484Z

cve-icon NVD

Status : Received

Published: 2025-12-04T22:15:46.610

Modified: 2025-12-04T22:15:46.610

Link: CVE-2025-11838

cve-icon Redhat

No data.