Impact
WatchGuard Dimension includes an authenticated SQL injection flaw in its audit report component. A user who has report administration permissions can craft requests that inject SQL, enabling the execution of arbitrary system commands under the privileges of the Dimension WebUI process. This leads to privilege escalation on the host and can compromise the entire network segment running the appliance.
Affected Systems
The vulnerability affects the WatchGuard Dimension product. No specific sub‑versions are listed as affected, but the official fix is available in Dimension 2.3.1, implying that earlier releases lack the patch.
Risk and Exploitability
The CVSS score of 8.6 indicates a high impact potential. Exploitation requires valid authentication and appropriate permissions, limiting it to users with report admin rights. While an EPSS score is not supplied, the lack of a KEV listing suggests a lower current exploitation rate; however, the possibility of internal exploitation remains high, warranting urgent remediation.
OpenCVE Enrichment