Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    EOL-Software program gefährdet Unternehmenssicherheit

    November 13, 2025

    The bioweapons story hidden amidst the OpenAI for-profit information

    November 13, 2025

    Processing Massive Datasets with Dask and Scikit-learn

    November 13, 2025
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»CISA Flags Important WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Assaults
    AI Ethics & Regulation

    CISA Flags Important WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Assaults

    Declan MurphyBy Declan MurphyNovember 13, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    CISA Flags Important WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Assaults
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Nov 13, 2025Ravie LakshmananVulnerability / Community Safety

    The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Wednesday added a crucial safety flaw impacting WatchGuard Fireware to its Recognized Exploited Vulnerabilities (KEV) catalog, based mostly on proof of energetic exploitation.

    The vulnerability in query is CVE-2025-9242 (CVSS rating: 9.3), an out-of-bounds write vulnerability affecting Fireware OS 11.10.2 as much as and together with 11.12.4_Update1, 12.0 as much as and together with 12.11.3 and 2025.1.

    “WatchGuard Firebox comprises an out-of-bounds write vulnerability within the OS iked course of which will enable a distant unauthenticated attacker to execute arbitrary code,” CISA mentioned in an advisory.

    Particulars of the vulnerability have been shared by watchTowr Labs final month, with the cybersecurity firm stating that the difficulty stems from a lacking size verify on an identification buffer used throughout the IKE handshake course of.

    DFIR Retainer Services

    “The server does try certificates validation, however that validation occurs after the weak code runs, permitting our weak code path to be reachable pre-authentication,” safety researcher McCaulay Hudson famous.

    There are at present no particulars on how the safety defect is being exploited and what is the scale of such efforts. In accordance with information from the Shadowserver Basis, greater than 54,300 Firebox cases stay weak to the crucial bug as of November 12, 2025, down from a excessive of 75,955 on October 19.

    Roughly 18,500 of those units are within the U.S., the scans reveal. Italy (5,400), the U.Ok. (4,000), Germany (3,600), and Canada (3,000) spherical up the highest 5. Federal Civilian Government Department (FCEB) companies are suggested to use WatchGuard’s patches by December 3, 2025.

    The event comes as CISA additionally added CVE-2025-62215 (CVSS rating: 7.0), a lately disclosed flaw in Home windows kernel, and CVE-2025-12480 (CVSS rating: 9.1), an improper entry management vulnerability in Gladinet Triofox, to the KEV catalog. Google’s Mandiant Risk Protection staff has attributed the exploitation of CVE-2025-12480 to a menace actor it tracks as UNC6485.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    EOL-Software program gefährdet Unternehmenssicherheit

    November 13, 2025

    SAP Pushes Emergency Patch for 9.9 Rated CVE-2025-42887 After Full Takeover Danger

    November 13, 2025

    ThreatBook Peer-Acknowledged as a Sturdy Performer within the 2025 Gartner® Peer Insights™ Voice of the Buyer for Community Detection and Response.

    November 13, 2025
    Top Posts

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025

    Meta resumes AI coaching utilizing EU person knowledge

    April 18, 2025
    Don't Miss

    EOL-Software program gefährdet Unternehmenssicherheit

    By Declan MurphyNovember 13, 2025

    Geräte mit Finish-of-Life-Software program (EOL) stellen nach wie vor ein weit verbreitetes Sicherheitsproblem in Unternehmen…

    The bioweapons story hidden amidst the OpenAI for-profit information

    November 13, 2025

    Processing Massive Datasets with Dask and Scikit-learn

    November 13, 2025

    Inside Robotiq’s newest software program updates

    November 13, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.