MEDIUM · 6.5

CVE-2018-0284

A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The ...

Vulnerability Description

A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
CiscoMeraki Mr 24 Firmware< 24.13
CiscoMeraki Mr 25 Firmware< 25.11
CiscoMeraki Mr-
CiscoMeraki Ms 10 Firmware< 10.20
CiscoMeraki Ms 9 Firmware< 9.37
CiscoMeraki Ms-
CiscoMeraki Mx 13 Firmware< 13.32
CiscoMeraki Mx 14 Firmware< 14.25
CiscoMeraki Mx 15 Firmware< 15.7
CiscoMeraki Mx-
CiscoMeraki Z1-
CiscoMeraki Z3-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-0284?

CVE-2018-0284 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The ...

How severe is CVE-2018-0284?

CVE-2018-0284 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-0284?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Meraki Mr 24 Firmware, Cisco Meraki Mr 25 Firmware, Cisco Meraki Mr, Cisco Meraki Ms 10 Firmware, Cisco Meraki Ms 9 Firmware.