CVE-2025-9242

Kritisch9.8Veröffentlicht am 17. September 2025

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

Aktiv ausgenutzt

  • Seit dem 12. Nov. 2025 im CISA-Katalog ausgenutzter Schwachstellen
  • US-Bundesbehörden müssen sie bis zum 3. Dez. 2025 beheben (BOD 22-01)
  • Erster Angriff 34 Tage nach der Veröffentlichung beobachtet
  • In Ransomware-Kampagnen eingesetzt

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Quelle: CISA KEV · 1. Mai 2026 20. Jan. 2026 11. Dez. 2025 9. Dez. 2025 12. Nov. 2025 21. Okt. 2025

CVSS-Score9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Schwachstellentyp (CWE)CWE-787
Herstellerwatchguard

Betroffene Produkte

HerstellerProduktVersionen
watchguardfireware< 12.11.4
watchguardfirebox m270
watchguardfirebox m290
watchguardfirebox m370
watchguardfirebox m390
watchguardfirebox m440
watchguardfirebox m4600
watchguardfirebox m470
watchguardfirebox m4800
watchguardfirebox m5600
watchguardfirebox m570
watchguardfirebox m5800
watchguardfirebox m590
watchguardfirebox m670
watchguardfirebox m690
watchguardfirebox nv5
watchguardfirebox t20
watchguardfirebox t25
watchguardfirebox t40
watchguardfirebox t45
watchguardfirebox t55
watchguardfirebox t70
watchguardfirebox t80
watchguardfirebox t85
watchguardfireboxcloud

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE-Datenbank