AI Security AI安全 7h ago Updated 2h ago 更新于 2小时前 41

WatchGuard Patches Critical Vulnerabilities WatchGuard 修复关键漏洞

WatchGuard patched over two dozen vulnerabilities in Fireware OS and Dimension, with five critical flaws enabling unauthenticated remote code execution and account takeover Three critical CVEs (CVE-2026-19313, CVE-2026-19318, CVE-2026-19315) affect the iked IKE daemon, involving heap overflow, stack overflow, and type confusion bugs A fourth critical flaw (CVE-2026-13086) in the Endpoint Protection Manager service and a fifth (CVE-2026-78174) in Dimension allow RCE and session/CSRF token theft r WatchGuard发布安全补丁,修复超过20个漏洞,包括5个可导致远程代码执行(RCE)和账户接管的关键漏洞 3个关键漏洞影响Fireware OS的iked进程(IKEv1/IKEv2协议处理),无需认证即可利用 漏洞类型包括堆缓冲区溢出(CVE-2026-19313)、栈缓冲区溢出(CVE-2026-19318)和类型混淆(CVE-2026-19315) WatchGuard Dimension存在低权限管理员可窃取超级管理员会话ID的漏洞(CVE-2026-78174) 目前未发现任何漏洞被野外利用,补丁已发布至Fireware OS 2026.2.2/12.12.2/12.5.20和

58
Hot 热度
65
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • WatchGuard patched over two dozen vulnerabilities in Fireware OS and Dimension, with five critical flaws enabling unauthenticated remote code execution and account takeover
  • Three critical CVEs (CVE-2026-19313, CVE-2026-19318, CVE-2026-19315) affect the iked IKE daemon, involving heap overflow, stack overflow, and type confusion bugs
  • A fourth critical flaw (CVE-2026-13086) in the Endpoint Protection Manager service and a fifth (CVE-2026-78174) in Dimension allow RCE and session/CSRF token theft respectively
  • All five critical vulnerabilities carry a CVSS score of 9.3 and are exploitable without authentication, though no active exploitation has been observed in the wild
  • Patches are available in Fireware OS versions 2026.2.2, 12.12.2, 12.5.20, and Dimension version 2.3.1

Why It Matters

This release underscores the persistent risk posed by network-facing cryptographic daemons like iked, which handle IKEv1/v2 VPN negotiations and remain attractive targets for unauthenticated RCE attacks. For security practitioners, it highlights the importance of promptly patching firewall and VPN infrastructure, especially when vulnerabilities require no authentication to exploit. The breadth of the patch (25+ vulnerabilities across multiple severity levels) also signals that comprehensive security audits of network appliances are essential.

Technical Details

  • iked process vulnerabilities: Three critical flaws in the Internet Key Exchange daemon — a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion bug (CVE-2026-19315) — all exploitable via specially crafted IKEv1/IKEv2 network traffic without authentication
  • Endpoint Protection Manager flaw: CVE-2026-13086 is a critical stack-based buffer overflow in the epm service, tied to the deprecated Mobile Security feature in Fireware OS
  • Dimension account takeover: CVE-2026-78174 allows low-privileged administrators to extract super admin session IDs and CSRF tokens, enabling full account takeover
  • Additional vulnerabilities: Seven high-severity DoS flaws (six in iked), five high-severity Dimension bugs (arbitrary command execution, passphrase tampering, DoS), and eleven medium-severity issues across both products
  • Patch versions: Fireware OS 2026.2.2, 12.12.2, 12.5.20; Dimension 2.3.1; all critical CVEs rated CVSS 9.3

Industry Insight

  • Network appliance vendors should prioritize hardening of cryptographic and authentication daemons, as unauthenticated RCE in components like iked represents a high-impact attack surface for threat actors
  • Organizations relying on WatchGuard Fireware OS and Dimension should treat this as an urgent patching opportunity, especially for internet-facing deployments where iked is exposed
  • The deprecation of the Mobile Security feature still carrying a critical vulnerability suggests that legacy and deprecated components within security products deserve continued scrutiny and timely removal

TL;DR

  • WatchGuard发布安全补丁,修复超过20个漏洞,包括5个可导致远程代码执行(RCE)和账户接管的关键漏洞
  • 3个关键漏洞影响Fireware OS的iked进程(IKEv1/IKEv2协议处理),无需认证即可利用
  • 漏洞类型包括堆缓冲区溢出(CVE-2026-19313)、栈缓冲区溢出(CVE-2026-19318)和类型混淆(CVE-2026-19315)
  • WatchGuard Dimension存在低权限管理员可窃取超级管理员会话ID的漏洞(CVE-2026-78174)
  • 目前未发现任何漏洞被野外利用,补丁已发布至Fireware OS 2026.2.2/12.12.2/12.5.20和Dimension 2.3.1

为什么值得看

WatchGuard防火墙和VPN设备在企业网络中广泛部署,这些漏洞可导致完全的系统接管,对网络安全从业者至关重要。漏洞无需认证即可利用,攻击门槛极低,企业需立即评估风险并更新补丁。

技术解析

iked进程是Fireware OS的核心IKE守护进程,负责处理IPsec VPN协商和加密密钥建立,3个关键漏洞均位于此进程。漏洞类型涵盖堆缓冲区溢出、栈缓冲区溢出和类型混淆,CVSS评分均为9.3,攻击者只需发送特制网络流量即可触发RCE。Endpoint Protection Manager(epm)服务存在栈缓冲区溢出漏洞(CVE-2026-13086),影响已弃用的Mobile Security功能。WatchGuard Dimension的漏洞允许低权限管理员提取超级管理员的会话ID和CSRF令牌,实现账户接管。补丁版本包括Fireware OS 2026.2.2、12.12.2、12.5.20以及Dimension 2.3.1。

行业启示

VPN和防火墙设备的安全漏洞直接影响企业网络边界安全,需优先评估和修补。无需认证的RCE漏洞表明攻击者可通过网络流量直接攻击,企业应加强流量监控和入侵检测。虽然目前未发现野外利用,但鉴于漏洞严重性,企业应主动更新补丁而非等待攻击发生。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全