Impact
An SSRF flaw exists in the WatchGuard Dimension Remote Backup Connection Test configuration. The flaw allows an attacker who has authenticated privileged access to the device to send requests to internal network hosts. By triggering the test, the attacker can enumerate exposed services on neighboring systems, gaining visibility into the internal network topology. The vulnerability does not grant code execution or direct compromise of the Dimension device itself, but it can be a foothold for further lateral movement or information gathering.
Affected Systems
WatchGuard Dimension devices running versions earlier than 2.3.1 are affected. The flaw resides in the Remote Backup Connection Test feature. Any deployment that has this feature enabled and accepts connections from authenticated privileged users may be vulnerable.
Risk and Exploitability
The CVSS vector scores a moderate 5.3, and no EPSS score is available. It is not catalogued in CISA KEV. Exploitation requires authenticated privileged access to the device and the ability to invoke the Remote Backup Connection Test. Once triggered, the attacker can discover internal services; the impact is primarily information disclosure and potential network enumeration. Due to the remote nature of the attack and the lack of direct RCE, the risk is moderate but should not be ignored in environments where internal service enumeration could lead to larger compromises.
OpenCVE Enrichment