Login Vulnerability in WatchGuard Dimension Affects User Account Security
CVE-2026-78617
6.3MEDIUM
What is CVE-2026-78617?
The web login endpoint of WatchGuard Dimension lacks effective rate limiting and account lockout mechanisms by default. This oversight allows attackers to engage in automated password guessing attacks against user accounts. Although an optional account lockout feature can mitigate brute-force attempts after a specified number of failed logins, it is not enabled out-of-the-box. Therefore, users are urged to review their security settings and enable account lockout features to enhance protection against unauthorized access.
Affected Version(s)
Dimension 2.0 < 2.3.1
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)
