Impact
WatchGuard Dimension's web login endpoint lacks effective rate limiting or default account lockout, so an attacker may systematically try many passwords until success, potentially compromising user accounts. The vulnerability stems from improper authentication management weaknesses. The consequence is loss of confidentiality due to unauthorized account access, and potential lateral movement within the network if privileged accounts are compromised.
Affected Systems
This flaw affects all installations of WatchGuard Dimension where the account lockout feature is not explicitly enabled. The vendor recommends upgrading to Dimension 2.3.1, which addresses the issue by enforcing proper rate limiting and an optional lockout configuration.
Risk and Exploitability
With a CVSS score of 6.3 the impact is medium, but the lack of built‑in lockout means attackers can attempt many guesses, especially if default settings are not altered. No EPSS data is available, and the vulnerability is not listed in CISA KEV, suggesting it has not yet been widely exploited. The most likely attack vector is remote, via standard web-based login traffic.
OpenCVE Enrichment