VDB
CVE-2018-0284
CVE-2018-0284
PUBLISHED
CVSS 4 MEDIUM
A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.
EPSS 0.16% · 36.8th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
0.16%
36.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | meraki_mx_15_firmware | 0, 0, 0 |
| cisco | meraki_mr_25_firmware | 0 |
| cisco | meraki_mr_24_firmware | 0 |
| Cisco | Cisco Meraki Z1 | <13.32 |
| Cisco | Cisco Meraki M5 | <9.37 |
| Cisco | Cisco Meraki MX | <13.32 |
| cisco | meraki_mx_14_firmware | 0, 0, 0 |
| Cisco | Cisco Meraki Z3 | <13.32 |
| cisco | meraki_ms_10_firmware | 0 |
| Cisco | Cisco Meraki MR | <24.13 |
| cisco | meraki_ms_9_firmware | 0 |
| cisco | meraki_mx_13_firmware | 0, 0, 0 |
Exploit Intelligence
Timeline
- Nov 8, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- 20181107 Cisco Meraki Local Status Page Privilege Escalation Vulnerability vendor-advisory
- 105878 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2018-0284 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-smc-auth-bypass advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-sbsw-privacc advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-cue advisory