PT-2018-1850 · Cisco · Cisco Meraki Ms+4

Published

2018-11-07

·

Updated

2019-10-09

·

CVE-2018-0284

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Meraki MR, MS, MX, Z1, and Z3 product lines (affected versions not specified)
Description The issue is related to the local status page functionality, where an authenticated, remote attacker could modify device configuration files by exploiting a vulnerability in handling requests to the local status page. This could allow the attacker to establish an interactive session to the device with elevated privileges, potentially leading to further compromise of the device or obtaining additional configuration data. The vulnerability is also associated with inadequate access control in the software of Cisco Meraki network devices.
Recommendations For Cisco Meraki MR, MS, MX, Z1, and Z3 product lines, consider restricting access to the local status page functionality until a fix is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01452
CVE-2018-0284

Affected Products

Cisco Meraki Mr
Cisco Meraki Ms
Cisco Meraki Mx
Cisco Meraki Z1
Cisco Meraki Z3