Watchguard
Watchguard Dimension: vulnerabilidades y CVE
Watchguard Dimension tiene 15 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses15
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86135 | Alta (7) | 0.25% | — | 8 sept 2026 | A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated… |
| CVE-2026-78618 | Media (6.9) | 0.43% | — | 28 ago 2026 | A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially crafted request. |
| CVE-2026-78617 | Media (6.3) | 0.41% | — | 28 ago 2026 | WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account… |
| CVE-2026-78616 | Media (4.8) | 0.30% | — | 28 ago 2026 | A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated… |
| CVE-2026-78615 | Media (4.6) | 0.47% | — | 28 ago 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with a specially crafted URL. |
| CVE-2026-78614 | Alta (8.6) | 0.71% | — | 28 ago 2026 | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the… |
| CVE-2026-78613 | Alta (8.6) | 0.62% | — | 28 ago 2026 | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the… |
| CVE-2026-78612 | Alta (8.6) | 0.71% | — | 28 ago 2026 | WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as… |
| CVE-2026-78610 | Alta (8.4) | 0.23% | — | 28 ago 2026 | WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to visit a crafted link or page can… |
| CVE-2026-78499 | Media (5.1) | 0.44% | — | 28 ago 2026 | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems. |
| CVE-2026-78495 | Media (5.3) | 0.39% | — | 28 ago 2026 | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Remote Backup Connection Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network… |
| CVE-2026-78174 | Crítica (9.3) | 0.43% | — | 28 ago 2026 | WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session… |
| CVE-2026-78103 | Media (5.1) | 0.49% | — | 28 ago 2026 | WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator… |
| CVE-2026-78047 | Media (5.1) | 0.44% | — | 28 ago 2026 | A stored cross-site scripting (XSS) vulnerability in WatchGuard Dimension's task scheduling feature allows a low-privileged authenticated administrator to inject arbitrary HTML/JavaScript into these fields, which then… |
| CVE-2026-13108 | Alta (8.7) | 0.25% | — | 28 ago 2026 | WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.