Dimension Log Server Configuration Lock Bypass Vulnerability
Summary #
WatchGuard Dimension provides a client-side lock/unlock UI control for management changes. The server-side configuration endpoint does not enforce this lock/unlock workflow state, allowing an authenticated administrator to submit configuration changes directly to the endpoint without first completing the UI unlock step. This allows an authenticated read-write administrator session to bypass the intended editing workflow and overwrite configuration changes being made by another concurrent administrator session.
Impact: An attacker who already holds an authenticated administrator session with read-write permissions can send configuration change requests directly to the Log Server configuration endpoint, bypassing the UI lock/unlock workflow. This does not grant any access beyond what the admin session already has, but it can result in one administrator's configuration changes overwriting or conflicting with another administrator's concurrent changes, undermining the integrity guarantee that the lock/unlock mechanism is intended to provide.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
Solution #
References #
Credits #
- Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder