CVE Database
/

CVE-2018-0284

Back to search

CVE-2018-0284

Published: Nov 8, 2018

Modified: Nov 26, 2024

PUBLISHED

Description

A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.

VendorProductVersions

Cisco

Cisco Meraki MR

affected
<24.13

Cisco

Cisco Meraki M5

affected
<9.37

Cisco

Cisco Meraki MX

affected
<13.32

Cisco

Cisco Meraki Z1

affected
<13.32

Cisco

Cisco Meraki Z3

affected
<13.32

Weaknesses (CWE)

References

105878
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now