Description
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Published: 2026-08-27
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure (Service Enumeration via SSRF)
Action: Patch
AI Analysis

Impact

WatchGuard Dimension allows an authenticated privileged user to send a test FTP connection request that the system forwards to arbitrary network destinations. Because the request is made from the server itself, the victim can probe for any service exposed on adjacent internal hosts. This can reveal hostnames, open ports, and potentially additional vulnerabilities. The weakness is a classic Server Side Request Forgery (CWE‑918). The impact is limited to the information discovered; there is no direct code execution or data modification asserted by the description.

Affected Systems

The affected product is WatchGuard Dimension. No specific version is listed in the CVE data, but the vendor’s official fix is release 2.3.1. Users should verify that their deployment is on or earlier than that version and plan to apply the patch if applicable.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate risk. EPSS is not available, but the vulnerability is not listed in CISA’s KEV catalog, suggesting no mass exploitation is documented. The attack requires authenticated privileged access, meaning that an attacker must have user credentials with the necessary rights. Once authenticated, the attacker can enumerate services on adjacent networks, which can aid in deeper network reconnaissance for future attacks.

Generated by OpenCVE AI on August 28, 2026 at 07:50 UTC.

Remediation

Vendor Solution

Dimension 2.3.1


OpenCVE Recommended Actions

  • Update WatchGuard Dimension to 2.3.1 or later to address the SSRF flaw.
  • Restrict privileged user access to the FTP Server Test Connection feature; revoke or limit rights for users who do not require it.
  • Configure or disable the test connection endpoint to only allow connections to localhost or approved IP ranges, or apply network segmentation to prevent internal enumeration.

Generated by OpenCVE AI on August 28, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Title Dimension SSRF via FTP Server Test Connection
First Time appeared Watchguard
Watchguard dimension
Weaknesses CWE-918
CPEs cpe:2.3:a:watchguard:dimension:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard dimension
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Watchguard Dimension
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-28T15:56:45.148Z

Reserved: 2026-08-24T17:20:04.411Z

Link: CVE-2026-78499

cve-icon Vulnrichment

Updated: 2026-08-28T14:33:05.861Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T02:16:23.443

Modified: 2026-08-28T20:19:58.173

Link: CVE-2026-78499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:13:09Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)