CyberRota Analysis
AI-GeneratedWatchGuard Dimension's web login endpoint is vulnerable due to a lack of default rate-limiting and account lockout mechanisms, enabling remote attackers to execute automated password guessing attacks. If the account lockout feature is activated, it can mitigate brute-force attempts, but this protection is not enabled by default. Organizations using WatchGuard Dimension should prioritize addressing this vulnerability to safeguard user accounts against unauthorized access.
Original NVD Description
WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against user accounts. If the account lockout setting is enabled, brute-force attempts are blocked after a defined number of failed attempts, but this setting is not enabled by default.