Impact
WatchGuard Dimension allows an authenticated privileged user to send a test FTP connection request that the system forwards to arbitrary network destinations. Because the request is made from the server itself, the victim can probe for any service exposed on adjacent internal hosts. This can reveal hostnames, open ports, and potentially additional vulnerabilities. The weakness is a classic Server Side Request Forgery (CWE‑918). The impact is limited to the information discovered; there is no direct code execution or data modification asserted by the description.
Affected Systems
The affected product is WatchGuard Dimension. No specific version is listed in the CVE data, but the vendor’s official fix is release 2.3.1. Users should verify that their deployment is on or earlier than that version and plan to apply the patch if applicable.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk. EPSS is not available, but the vulnerability is not listed in CISA’s KEV catalog, suggesting no mass exploitation is documented. The attack requires authenticated privileged access, meaning that an attacker must have user credentials with the necessary rights. Once authenticated, the attacker can enumerate services on adjacent networks, which can aid in deeper network reconnaissance for future attacks.
OpenCVE Enrichment