PT-2018-1850 · Cisco · Cisco Meraki Ms+4
Published
2018-11-07
·
Updated
2019-10-09
·
CVE-2018-0284
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Meraki MR, MS, MX, Z1, and Z3 product lines (affected versions not specified)
Description
The issue is related to the local status page functionality, where an authenticated, remote attacker could modify device configuration files by exploiting a vulnerability in handling requests to the local status page. This could allow the attacker to establish an interactive session to the device with elevated privileges, potentially leading to further compromise of the device or obtaining additional configuration data. The vulnerability is also associated with inadequate access control in the software of Cisco Meraki network devices.
Recommendations
For Cisco Meraki MR, MS, MX, Z1, and Z3 product lines, consider restricting access to the local status page functionality until a fix is available.
As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Meraki Mr
Cisco Meraki Ms
Cisco Meraki Mx
Cisco Meraki Z1
Cisco Meraki Z3