GHSA-w44g-4gmf-m2ww · Severity: high — A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote...
A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2
Conclusion & alert: CVE-2026-13084 is rated Moderate Risk (53.5/100): CVSS High severity. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
EPSS has not published a score for this CVE yet—common while NVD analysis or FIRST scoring is still pending. Monitor daily updates and reassess once scores appear.
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 4.0 | HIGH |
|
— | — | 5d1c2695-1a31-4499-88ae-e847036fd7e3 |
GHSA-w44g-4gmf-m2ww · Severity: high — A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| watchguard | fireware_os | >= 11.10.2, <= 11.12.4+541730 | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.10.2 |
| watchguard | fireware_os | >= 12.0, <= 12.12 | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0 |
| watchguard | fireware_os | >= 12.5, <= 12.5.18 | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5 |
| watchguard | fireware_os | >= 2025.1, <= 2026.2 | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1 |