ZeroHour

CVE-2026-13108

moderate

Unauthenticated TCP SYN-flood denial-of-service in WatchGuard Dimension log service

CVSS 4.0
8.7 high
EPSS
<1%p17
Published
()
Modified
AI analysis

WatchGuard Dimension, the vendor's centralized log-management and network-visibility appliance, is vulnerable to a denial-of-service condition (CWE-400, uncontrolled resource consumption) in its log listening service. A remote, unauthenticated attacker can trigger the flaw by sending a high volume of TCP SYN packets to that service, exhausting its resources until the service or appliance becomes unavailable. The impact is availability-only: CVSS 4.0 rates it 8.7 High with high availability impact but no confidentiality or integrity impact, so the attacker gains a service outage, not access to log data. Any organization running WatchGuard Dimension is affected, especially deployments where the log listening service is reachable from untrusted networks such as the internet. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is known, and EPSS estimates only a ~0.3% probability of exploitation within 30 days.

What to do: Watch WatchGuard's security portal for the CVE-2026-13108 advisory and apply the vendor's patch/update promptly (no fixed version is specified in the available data). In the meantime, restrict access to the log listening service to trusted log sources (e.g., Firebox senders or VPN paths) with firewall/ACL rules, and rate-limit or drop unsolicited inbound TCP connections. Inventory deployments to determine whether the log service is internet-reachable, since only exposed instances face meaningful risk.

Affected
WatchGuard Dimension
Estimated exposure
moderatelikely tens of thousands of Dimension deployments (order-of-magnitude estimate; no authoritative public install counts) — Dimension is WatchGuard's standard centralized log/visibility appliance commonly deployed alongside its large Firebox firewall install base, so a moderate fraction of that base plausibly runs Dimension, though only instances with the log…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WatchGuard Dimension is susceptible to a denial-of-service condition when an attacker sends a high volume of TCP SYN packets to the log listening service.

Weakness
CWE-400
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.