Impact
WatchGuard Dimension implements a client‑side lock/unlock UI to protect configuration changes, but the server‑side configuration endpoint does not enforce that workflow. An authenticated administrator can therefore submit configuration changes directly to the endpoint without completing the UI unlock step. This allows a read‑write administrator to bypass the intended editing workflow and overwrite configuration changes made by another concurrent administrator, potentially corrupting or inadvertently altering the system configuration.
Affected Systems
The vulnerability affects the WatchGuard Dimension appliance. All versions released before 2.3.1 are impacted. The vendor has issued a fix in Dimension 2.3.1.
Risk and Exploitability
The vulnerability is assigned a medium CVSS score of 5.1. EPSS information is not available and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must be an authenticated administrator with read‑write privileges. The risk is moderate due to the requirement of valid credentials, but the impact on configuration integrity could lead to service disruptions or misconfiguration if an attacker intentionally modifies settings.
OpenCVE Enrichment