Executive brief
WatchGuard Dimension is a security and network management platform used by organizations to monitor and control network infrastructure. This vulnerability allows an authenticated administrator to bypass normal network boundary controls and scan for exposed services on adjacent network systems, potentially discovering unpatched systems or unauthorized devices on the network.
Technical details
A server-side request forgery (SSRF) vulnerability exists in WatchGuard Dimension's Email Server Test configuration feature. An authenticated user with administrative privileges can craft requests that force the Dimension server to perform HTTP requests to arbitrary network addresses, allowing enumeration of services on adjacent network systems. The vulnerability requires authentication and administrative privileges to exploit. An attacker can discover exposed internal network services and their versions, which can be used for further network reconnaissance or targeted attacks. The issue is fixed in Dimension version 2.3.1.
Affected products
- WatchGuard Dimension 2.0 to 2.3.0
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Fixed in version 2.3.1