PT-2026-82856 · Watchguard · Dimension
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
WatchGuard Dimension (affected versions not specified)
Description
The web login endpoint does not enforce effective rate-limiting or account lockout by default. This allows a remote attacker to perform automated password guessing against user accounts. While an account lockout setting exists to block brute-force attempts after a defined number of failed attempts, it is not enabled by default.
Recommendations
Enable the account lockout setting to block automated password guessing attempts.
Fix
Improper Restriction of Excessive Authentication Attempts
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dimension