Description
A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.
Published: 2018-11-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-1107 A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.
History

Tue, 26 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Meraki Mr Meraki Mr 24 Firmware Meraki Mr 25 Firmware Meraki Ms Meraki Ms 10 Firmware Meraki Ms 9 Firmware Meraki Mx Meraki Mx 13 Firmware Meraki Mx 14 Firmware Meraki Mx 15 Firmware Meraki Z1 Meraki Z3
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-26T14:23:01.925Z

Reserved: 2017-11-27T00:00:00.000Z

Link: CVE-2018-0284

cve-icon Vulnrichment

Updated: 2024-08-05T03:21:15.285Z

cve-icon NVD

Status : Modified

Published: 2018-11-08T16:29:00.227

Modified: 2024-11-21T03:37:53.637

Link: CVE-2018-0284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses