Description
WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service.
Published: 2026-08-27
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WatchGuard Dimension can be rendered unavailable when an attacker sends a large number of TCP SYN packets to its log listening service. The vulnerability allows a remote adversary to consume network resources or trigger a program fault, leading to a denial of service. The weakness is the improper handling of excessive network traffic, as reflected by CWE‑400.

Affected Systems

The affected system is WatchGuard's Dimension platform. All releases before the officially released 2.3.1 patch contain the flaw; the vendor’s advisory does not list specific minor revisions, so any unpatched Dimension deployment is susceptible.

Risk and Exploitability

This vulnerability has a CVSS score of 8.7, indicating a high severity. The exploitation probability is currently unknown as EPSS data is missing, but the requirement for a high volume of SYN packets suggests that coordinated traffic from an attacker or botnet could achieve exploitation. The flaw is not present in the CISA KEV catalog, so there are no known widespread compromised instances. The typical attack vector is a remote network attack that overwhelms the Dimension log service, for which deploying rate‑limiting controls mitigates the impact.

Generated by OpenCVE AI on August 28, 2026 at 05:35 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


Vendor Workaround

The vulnerability exploit requires a high volume of TCP SYN packets over a short duration and is mitigated by deploying the Dimension server behind a firewall that provides rate limiting protections.


OpenCVE Recommended Actions

  • Apply the vendor‑provided patch, upgrading Dimension to version 2.3.1.
  • If an immediate patch cannot be applied, place the Dimension server behind a firewall that enforces rate limiting on inbound TCP SYN traffic to the log listening port.
  • Restrict the log listening interface to trusted IP ranges or disable the service entirely if it is not required for operations.
  • Monitor inbound SYN rates and configure alerts for anomalous spikes that could indicate a DoS attempt.

Generated by OpenCVE AI on August 28, 2026 at 05:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service.
Title Dimension Denial-of-Service
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-400
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:30.552Z

Reserved: 2026-06-23T19:57:31.300Z

Link: CVE-2026-13108

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:20.323

Modified: 2026-08-28T02:16:20.323

Link: CVE-2026-13108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:15:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption