Description
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Published: 2026-08-27
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An SSRF flaw exists in the WatchGuard Dimension Remote Backup Connection Test configuration. The flaw allows an attacker who has authenticated privileged access to the device to send requests to internal network hosts. By triggering the test, the attacker can enumerate exposed services on neighboring systems, gaining visibility into the internal network topology. The vulnerability does not grant code execution or direct compromise of the Dimension device itself, but it can be a foothold for further lateral movement or information gathering.

Affected Systems

WatchGuard Dimension devices running versions earlier than 2.3.1 are affected. The flaw resides in the Remote Backup Connection Test feature. Any deployment that has this feature enabled and accepts connections from authenticated privileged users may be vulnerable.

Risk and Exploitability

The CVSS vector scores a moderate 5.3, and no EPSS score is available. It is not catalogued in CISA KEV. Exploitation requires authenticated privileged access to the device and the ability to invoke the Remote Backup Connection Test. Once triggered, the attacker can discover internal services; the impact is primarily information disclosure and potential network enumeration. Due to the remote nature of the attack and the lack of direct RCE, the risk is moderate but should not be ignored in environments where internal service enumeration could lead to larger compromises.

Generated by OpenCVE AI on August 28, 2026 at 07:30 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Upgrade WatchGuard Dimension to version 2.3.1 or later to apply the SSRF fix.
  • If an upgrade cannot be performed immediately, disable or restrict the Remote Backup Connection Test feature so that only authorized users can invoke it.
  • Review and tighten access controls to ensure only the minimum required privileged accounts can use the backup test functionality.

Generated by OpenCVE AI on August 28, 2026 at 07:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Title Dimension Server-Side Request Forgery via Remote Backup Connection Test
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-918
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:26:31.170Z

Reserved: 2026-08-24T17:07:25.894Z

Link: CVE-2026-78495

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:23.197

Modified: 2026-08-28T02:16:23.197

Link: CVE-2026-78495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:45:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)