Executive brief
WatchGuard Dimension is a network monitoring and management platform accessed through a web interface. The login endpoint lacks effective brute-force protections by default, allowing attackers to automatically guess user credentials without being blocked after repeated failed attempts. While an optional account lockout feature exists, it is disabled by default, leaving organizations vulnerable to account compromise unless they manually enable this protection.
Technical details
The vulnerability exists in WatchGuard Dimension's web login endpoint, which fails to implement rate-limiting or enforce account lockout on failed authentication attempts by default (CWE-307: Improper Restriction of Excessive Authentication Attempts). An unauthenticated remote attacker can exploit this over the network to conduct automated password-guessing attacks against user accounts. Although Dimension offers an optional account lockout mechanism that blocks further attempts after a configured threshold, this protection is not enabled by default, making it ineffective for organizations that do not explicitly configure it. The issue is resolved in Dimension 2.3.1 and later versions.
Affected products
- WatchGuard Dimension < 2.3.1
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Fixed in Dimension 2.3.1