Impact
WatchGuard Dimension contains an authenticated SQL injection in the log viewer feature. When an attacker with report administration privileges sends a crafted request, the vulnerability allows execution of arbitrary commands as the Dimension WebUI process user.
Affected Systems
All versions of WatchGuard Dimension prior to the 2.3.1 release are affected. The CVE specifically references the Dimension product from WatchGuard.
Risk and Exploitability
Based on the description, it is inferred that the attacker must be an authenticated user with report administration permissions, and the exploitation involves sending specially crafted requests to the log viewer endpoint. The vulnerability has a CVSS score of 8.6, indicating high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. Exploitation requires legitimate authentication with report administration permissions, so it is an insider or credential-compromise threat rather than remote exploitation. The impact includes full system compromise through command execution as the Dimension WebUI process user.
OpenCVE Enrichment