Cisco Meraki Local Status Page Privilege Escalation Vulnerability
CVE-2018-0284

6.5MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
8 November 2018

Badges

👾 Exploit Exists

Summary

A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.

Affected Version(s)

Cisco Meraki M5 <9.37

Cisco Meraki MR <24.13

Cisco Meraki MX <13.32

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.