---
id: CVE-2024-5974
title: >-
  A buffer overflow in WatchGuard Fireware OS could may allow an authenticated
  remote attacker with privileged management access to execute arbitrary code
  with system privileges on the firewall.

  This issue affects Fireware OS: from 11.9.6 …
summary: >-
  A buffer overflow in WatchGuard Fireware OS could may allow an authenticated
  remote attacker with privileged management access to execute arbitrary code
  with system privileges on the firewall.

  This issue affects Fireware OS: from 11.9.6 …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
  - CWE-120
vendor: watchguard
product: fireware
affected:
  - 'fireware >= 11.9.4, < 12.5.12'
  - 'fireware >= 12.6, < 12.10.4'
  - fireware = 12.5.12
patched:
  - fireware 12.10.4
published: '2024-07-09'
updated: '2026-08-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-5974'
references:
  - url: 'https://psirt.watchguard.com/CVE-2024-5974'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
  - url: 'https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00011'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
  - url: 'https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00011'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01044
epssPercentile: 0.62671
ingestedAt: '2026-08-07T22:17:36.799Z'
---

## Overview

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall.
This issue affects Fireware OS: from 11.9.6 through 12.10.3.

## Affected

- `fireware >= 11.9.4, < 12.5.12`
- `fireware >= 12.6, < 12.10.4`
- `fireware = 12.5.12`

## Remediation

Upgrade past the affected range:

- `fireware 12.10.4`
