Junglewise Threat Intelligence

CVE-2026-13108: WatchGuard Dimension denial of service via TCP SYN flood

CVE-2026-13108 · Severity: info · CVSS 8.7 · Published 2026-08-28

Technologies: Watchguard Dimension. Vendors: Watchguard.

Executive brief

WatchGuard Dimension is a logging and analytics service used to monitor security appliances and network activity. An attacker can flood the log listening service with a high volume of TCP connection attempts, overwhelming the service and rendering it unavailable to legitimate users. No exploitation in the wild has been observed, but the vulnerability requires a network firewall to be properly deployed to mitigate.

Technical details

This is an uncontrolled resource consumption vulnerability (CWE-400) in the log listening service of WatchGuard Dimension. An attacker on the network can send a high volume of TCP SYN packets to trigger a denial-of-service condition by exhausting server resources. The vulnerability affects versions 2.0 through 2.3.0; the attack vector is network-based with no authentication requirement. Mitigation is available through upgrading to version 2.3.1 or deploying the Dimension server behind a firewall with rate-limiting protections.

Affected products

  • WatchGuard Dimension 2.0 through 2.3.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Version 2.3.1 available

References

Related threats