Impact
WatchGuard Dimension can be rendered unavailable when an attacker sends a large number of TCP SYN packets to its log listening service. The vulnerability allows a remote adversary to consume network resources or trigger a program fault, leading to a denial of service. The weakness is the improper handling of excessive network traffic, as reflected by CWE‑400.
Affected Systems
The affected system is WatchGuard's Dimension platform. All releases before the officially released 2.3.1 patch contain the flaw; the vendor’s advisory does not list specific minor revisions, so any unpatched Dimension deployment is susceptible.
Risk and Exploitability
This vulnerability has a CVSS score of 8.7, indicating a high severity. The exploitation probability is currently unknown as EPSS data is missing, but the requirement for a high volume of SYN packets suggests that coordinated traffic from an attacker or botnet could achieve exploitation. The flaw is not present in the CISA KEV catalog, so there are no known widespread compromised instances. The typical attack vector is a remote network attack that overwhelms the Dimension log service, for which deploying rate‑limiting controls mitigates the impact.
OpenCVE Enrichment