Vulnerability Description
A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Meraki Mr 24 Firmware | < 24.13 |
| Cisco | Meraki Mr 25 Firmware | < 25.11 |
| Cisco | Meraki Mr | - |
| Cisco | Meraki Ms 10 Firmware | < 10.20 |
| Cisco | Meraki Ms 9 Firmware | < 9.37 |
| Cisco | Meraki Ms | - |
| Cisco | Meraki Mx 13 Firmware | < 13.32 |
| Cisco | Meraki Mx 14 Firmware | < 14.25 |
| Cisco | Meraki Mx 15 Firmware | < 15.7 |
| Cisco | Meraki Mx | - |
| Cisco | Meraki Z1 | - |
| Cisco | Meraki Z3 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105878Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- http://www.securityfocus.com/bid/105878Third Party AdvisoryVDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2018-0284?
CVE-2018-0284 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The ...
How severe is CVE-2018-0284?
CVE-2018-0284 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-0284?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Meraki Mr 24 Firmware, Cisco Meraki Mr 25 Firmware, Cisco Meraki Mr, Cisco Meraki Ms 10 Firmware, Cisco Meraki Ms 9 Firmware.