CVE-2024-5974: WatchGuard Fireware

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10.3.

Affected products

  • WatchGuard Fireware: from 11.9.4, before 12.5.12 (fixed in 12.5.12); from 12.6, before 12.10.4 (fixed in 12.10.4); version 12.5.12 only

Published 2024-07-09. Last modified 2026-08-07.