WatchGuard Firebox IKEv2 RCE
- شناسه CVE: CVE-2025-9242
- شدت: بحرانی
- امتیاز CVSS: 9.6
- فروشنده/سازنده: WatchGuard
RCEFirewallIKEv2WatchGuard
A critical heap-based buffer overflow in the IKEv2 VPN daemon of WatchGuard Firebox appliances allows unauthenticated remote code execution.
## Vulnerability Overview
The vulnerability exists in the IKEv2 protocol implementation of WatchGuard Fireware OS. An unauthenticated attacker can send specially crafted IKEv2 INIT packets to the VPN service, triggering a heap buffer overflow that leads to arbitrary code execution with root privileges.
## Technical Details
- **Type:** Heap Buffer Overflow (CWE-122)
- **Vulnerable Service:** IKEv2 VPN daemon (iked)
- **Root Cause:** Insufficient validation of the Security Association (SA) payload length in IKEv2 INIT packets. An oversized SA payload overflows a heap-allocated buffer used for proposal parsing.
- **Attack Vector:** Network (any device with IKEv2 VPN enabled and reachable)
- **Exploitation:** Reliable exploitation achieved through heap grooming techniques. The overflow allows overwriting adjacent heap metadata, enabling arbitrary write and eventually code execution.
## Impact
- Full compromise of the WatchGuard Firebox appliance
- Access to all network traffic passing through the firewall
- Pivot to internal networks
- Modification of firewall rules
## Affected Versions
- Fireware OS 12.8.x before 12.8.2 Update 3
- Fireware OS 12.10.x before 12.10.4 Update 1
## Vulnerability Overview
The vulnerability exists in the IKEv2 protocol implementation of WatchGuard Fireware OS. An unauthenticated attacker can send specially crafted IKEv2 INIT packets to the VPN service, triggering a heap buffer overflow that leads to arbitrary code execution with root privileges.
## Technical Details
- **Type:** Heap Buffer Overflow (CWE-122)
- **Vulnerable Service:** IKEv2 VPN daemon (iked)
- **Root Cause:** Insufficient validation of the Security Association (SA) payload length in IKEv2 INIT packets. An oversized SA payload overflows a heap-allocated buffer used for proposal parsing.
- **Attack Vector:** Network (any device with IKEv2 VPN enabled and reachable)
- **Exploitation:** Reliable exploitation achieved through heap grooming techniques. The overflow allows overwriting adjacent heap metadata, enabling arbitrary write and eventually code execution.
## Impact
- Full compromise of the WatchGuard Firebox appliance
- Access to all network traffic passing through the firewall
- Pivot to internal networks
- Modification of firewall rules
## Affected Versions
- Fireware OS 12.8.x before 12.8.2 Update 3
- Fireware OS 12.10.x before 12.10.4 Update 1
نرمافزارهای تحت تأثیر
- WatchGuard Firebox
- Fireware OS