Impact
A blind server‑side request forgery (SSRF) flaw in WatchGuard Dimension’s database test configuration allows an authenticated privileged user to enumerate exposed network services on adjacent systems. The vulnerability is a form of information disclosure and fits CWEs 208 (Information Exposure Through Authentication) and 918 (Server‑Side Request Forgery). By probing internal addresses the attacker can discover reachable services, thereby facilitating lateral movement or targeted attacks.
Affected Systems
WatchGuard Dimension Database Server, versions prior to 2.3.1. The fix is delivered in VERSION 2.3.1 and later releases.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity; there is no public exploit for this vulnerability, and it was not listed in CISA’s KEV catalog. The EPSS score is currently unavailable, so the probability of exploitation cannot be quantified. The likely attack path requires an authenticated privileged account that can use the test‑connection feature; however, the damage is limited to information disclosure and does not provide immediate code execution.
OpenCVE Enrichment