Impact
The vulnerability is a Cross‑Site Request Forgery that permits a remote attacker to coerce an authenticated administrator into creating a database snapshot. When triggered, the snapshot consumes significant disk space and I/O, potentially exhausting system resources and causing a service interruption. The lack of proper resource limits also contributes to a denial‑of‑service outcome while the database remains otherwise operational.
Affected Systems
The flaw exists in WatchGuard Dimension, all builds prior to 2.3.1. Administrators with access to the web console for snapshot creation are the primary risk group, and the vulnerability is confined to the snapshot creation endpoint.
Risk and Exploitability
The CVSS score of 7 indicates a high threat level. Exploitation requires an authenticated admin session and user interaction, so the EPSS score is unavailable but targeted attacks are viable. The feature is not listed in the CISA KEV catalog, suggesting no known active exploits yet, yet attackers can craft a malicious link that will be executed by an unwary admin, leading to a resource‑heavy snapshot and eventual denial of service.
OpenCVE Enrichment