Executive brief
WatchGuard Dimension is a network management and monitoring platform used by organizations to oversee their infrastructure. An authenticated administrator with elevated privileges can exploit an SSRF vulnerability in the FTP Server Test configuration feature to discover and enumerate services running on adjacent network systems, potentially exposing internal infrastructure details to unauthorized discovery.
Technical details
A server-side request forgery (CWE-918) vulnerability exists in WatchGuard Dimension's FTP Server Test feature within the configuration interface. The vulnerability allows an authenticated privileged attacker to craft requests that cause the Dimension server to make arbitrary connections to adjacent network systems, enabling enumeration of exposed network services. Attack requires authentication and elevated privileges. An attacker can discover internal services and network topology without direct access to those systems. The vulnerability is patched in Dimension version 2.3.1 and later.
Affected products
- WatchGuard Dimension >=2.0, <2.3.1
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Fixed in Dimension 2.3.1