Impact
An authenticated SQL injection flaw exists in the scheduled report feature of WatchGuard Dimension. An attacker who is logged in and has report administration permissions can send specially crafted requests that cause the Dimension WebUI process to execute arbitrary commands. The vulnerability is classified under CWE-89 and CWE-502 and is rated with a CVSS score of 8.6, indicating high severity.
Affected Systems
This weakness affects the WatchGuard Dimension product. All deployments running versions older than the 2.3.1 release are vulnerable, as the vendor’s official fix is provided in that version. No specific sub‑components other than the scheduled report functionality are mentioned.
Risk and Exploitability
The CVSS score of 8.6 highlights high severity, but the EPSS score is not available, making it difficult to gauge current exploitation probability. Because the attack requires authenticated access with report‑administration rights, the vector is likely internal or requires compromised credentials. The vulnerability is not listed in the CISA KEV catalog, suggesting there is no known active exploitation in the wild. Nonetheless, the ability to execute arbitrary commands warrants immediate attention.
OpenCVE Enrichment