WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs
Summary #
WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover.
Impact: By harvesting the Super Administrator's session ID and CSRF token from the diagnostic log, an authenticated low-privileged Dimension Administrator can fully impersonate the Super Administrator, bypassing all access control restrictions. This allows the attacker to access and modify the Access Management section, create, delete, or alter any user or group, change system-wide configuration, lock out legitimate administrators, and gain persistent full administrative control over the Dimension appliance.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Dimension | >= 2.0, < 2.3.1 | >= 2.3.1 |
Weakness Type and Impact #
Exploitation Status #
Solution #
References #
Credits #
- Simone Paganessi (https://www.linkedin.com/in/simonepaganessi)finder