Impact
A server‑side request forgery flaw exists in the WatchGuard Dimension Email Server Test configuration. The vulnerability allows an authenticated privileged user to craft requests that force the device to reach arbitrary internal URLs, enabling enumeration of exposed network services on adjacent hosts. The impact is the discovery of internal services, which can facilitate further attacks by revealing potential attack vectors within the internal network.
Affected Systems
The affected product is WatchGuard Dimension, with releases prior to Version 2.3.1 presumably impacted. No specific sub‑versions are listed, but the vendor’s advisory recommends applying Version 2.3.1 to remediate.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no currently known widespread exploitation. Exploitation requires authenticated privileged access to the Dimension appliance, so limiting privileged accounts and enforcing strong authentication mitigates risk. An attacker can use the SSRF vector to probe internal network services but cannot gain execution or arbitrary code unless other flaws are present.
OpenCVE Enrichment