Impact
A business logic flaw in WatchGuard Dimension enables an authenticated administrator to trigger a series of backend operations in a single request. The flaw permits execution of multiple privileged actions that the administrator would normally need to initiate separately, effectively giving the attacker the ability to perform unintended or potentially harmful operations within the system. The associated weaknesses are improper access control (CWE-284) and improper authorization (CWE-841).
Affected Systems
The vulnerability affects WatchGuard Dimension installations that have not yet applied the official update, which addresses the flaw in version 2.3.1. Specific affected versions are not listed in the advisory, but any release prior to the patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the vulnerability is not currently listed in the CISA KEV catalog. While no EPSS score is available, the requirement for administrator authentication suggests that the attacker must first compromise or legitimately assume an admin role. The flaw could be exploited to run arbitrary backend processes, potentially compromising data integrity or availability, but the high privilege requirement limits the scope to systems where an attacker can gain administrative access.
OpenCVE Enrichment