Impact
WatchGuard Dimension records session identifiers for logged-in users in its web UI diagnostic log without redaction. A low‑privileged Administrator can read this log while a Super Administrator is logged in and then extract the super‑administrator’s session token, enabling an account takeover. The defect is a classic information‑exposure flaw (CWE‑200) that compounds poor permission controls (CWE‑269) and inadequate logging protections (CWE‑532).
Affected Systems
All WatchGuard Dimension installations that predate the release of v2.3.1 are vulnerable, as they retain the unredacted session‑token logging behavior described. WatchGuard recommends upgrading to v2.3.1 or newer to eliminate the fault.
Risk and Exploitability
The CVSS base score of 9.3 signals a critical risk. The EPSS score is currently not available, so the current exploitation probability is uncertain. The vulnerability is likely exploitable via the web UI diagnostic log, requiring only that an attacker possess low‑privileged Administrator rights and that a Super Administrator be actively logged in. It is not listed in CISA’s KEV catalog, but the severity and potential for account takeover warrant immediate remediation.
OpenCVE Enrichment