CVE-2024-5974
published 2024-07-09CVE-2024-5974: A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with…
PriorityP346high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.04%
61.7th percentile
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall.
This issue affects Fireware OS: from 11.9.6 through 12.10.3.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| watchguard | fireware | — | — |
| watchguard | fireware | >= 11.9.4 < 12.5.12 | 12.5.12 |
| watchguard | fireware | >= 12.6 < 12.10.4 | 12.10.4 |
| watchguard | fireware_os | >= 11.9.4 < 12.10.4 | 12.10.4 |
| watchguard | fireware_os | >= 12.0 < 12.5.12+701324 | 12.5.12+701324 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WatchGuard Fireware OS up to 12.5.12+687697/12.10.3 buffer overflow (wgsa-2024-0001)
vuldb·2026-08-08·CVSS 7.2
CVE-2024-5974 [HIGH] WatchGuard Fireware OS up to 12.5.12+687697/12.10.3 buffer overflow (wgsa-2024-0001)
A vulnerability has been found in WatchGuard Fireware OS up to 12.5.12+687697/12.10.3 and classified as critical. This affects an unknown part. Performing a manipulation results in buffer overflow.
This vulnerability is known as CVE-2024-5974. Remote exploitation of the attack is possible. No exploit is available.
GHSA
GHSA-qqv6-xcxx-rcc7: A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary co
ghsa_unreviewed·2024-07-09
CVE-2024-5974 [HIGH] CWE-120 GHSA-qqv6-xcxx-rcc7: A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary co
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall.
This issue affects Fireware OS: from 11.9.6 through 12.10.3.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-09
Published