Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication
Vulnerability Description
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
释放后使用
Vulnerability Title
WatchGuard Fireware OS 资源管理错误漏洞
Vulnerability Description
WatchGuard Fireware OS是美国WatchGuard公司的一款网络防火墙的操作系统。 WatchGuard Fireware OS存在资源管理错误漏洞,该漏洞源于LDAP认证中存在竞争条件导致释放后重用,可能导致远程未经验证攻击者在配置了使用外部LDAP认证服务器的IKEv2移动VPN的Firebox上执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A