Impact
The vulnerability is a stored cross‑site scripting flaw in the Trusted Certificate Authority configuration of WatchGuard Dimension. An administrator who authenticates to the web interface can insert malicious JavaScript into a certificate entry; when another authenticated administrator later views or downloads the certificate, the embedded script executes in their browser. This allows the attacker to run arbitrary code within the context of the victim administrator’s session, potentially leading to credential theft, session hijacking, or other covert operations. The weakness is a classic input validation flaw identified by CWE‑79.
Affected Systems
The flaw affects WatchGuard Dimension devices. Vendor documentation recommends applying the update to version 2.3.1 to remediate the issue. No specific affected version range is listed in the advisory, so any installation that has not yet been updated to 2.3.1 should be considered at risk.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity level. The attack requires valid administrator credentials and access to the Trusted CA certificate configuration, and the exploit is not publicly available. EPSS data is not provided and the flaw is not marked in the CISA KEV catalog, suggesting it is not a current targeted or widely‑used threat vector. Nonetheless, because the vulnerability allows arbitrary JavaScript execution in the browser of privileged users, the potential impact on confidential administrative sessions warrants prompt attention.
OpenCVE Enrichment