CVE-2026-13108
8.7WatchGuard · Dimension
WatchGuard Dimension is vulnerable to a denial-of-service attack, where an unauthenticated attacker can flood the log listening service with TCP SYN packets to disrupt availability.
Executive summary
WatchGuard Dimension is affected by a high-severity denial-of-service vulnerability that allows unauthenticated attackers to disrupt system availability via TCP SYN flooding.
Vulnerability
This is a resource exhaustion vulnerability (CWE-400) occurring in the log listening service of WatchGuard Dimension. An unauthenticated attacker can trigger this condition by sending a high volume of TCP SYN packets, leading to a denial-of-service state.
Business impact
Successful exploitation of this vulnerability results in a denial-of-service condition, effectively taking the log management system offline. With a CVSS score of 8.7, this flaw poses a significant risk to operational continuity, as it prevents the ingestion and monitoring of critical security logs. Such an outage could hinder incident response efforts and compromise the visibility of the network security posture.
Remediation
Immediate Action: Update WatchGuard Dimension to version 2.3.1 or later to resolve the underlying resource handling flaw.
Proactive Monitoring: Monitor system logs and network traffic for unusual spikes in TCP SYN packets directed at the log listening service.
Compensating Controls: Implement rate limiting or firewall rules to restrict traffic to the log listening service to known, trusted IP addresses, which can serve as a temporary mitigation against flood-based attacks.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Given the high CVSS score and the potential for service disruption, organizations should prioritize the deployment of the vendor-provided patch. Updating to version 2.3.1 is the only definitive method to remediate this vulnerability and restore system resilience against SYN flood attacks.
More WatchGuard CVEs
Sources
Originally found and disclosed by Alessandro Vannini, IT4YOU Cybersecurity, per the CVE Program record.