Impact
This vulnerability allows an attacker to alter an authenticated global administrator's passphrase through a crafted link or page, without the administrator’s consent. The lack of CSRF protection enables the attacker to assume control of the administrator account or lock the legitimate administrator out, leading to potential full system compromise.
Affected Systems
WatchGuard Dimension web UI. All versions prior to the released patch are affected. The official fix is available as Dimension 2.3.1, which implements CSRF protection on the passphrase change endpoint.
Risk and Exploitability
The CVSS score of 8.4 classifies this issue as high severity. Although a current EPSS value is not published, the lack of a CISA KEV listing does not reduce its potential impact. The exploitation requires only that an attacker host a malicious page and persuade a legitimate administrator to click or visit that page while logged in. The successful attack results in the attacker choosing the new passphrase, effectively granting full administrative control or denying the legitimate administrator access.
OpenCVE Enrichment