VDB

CVE-2018-0284

CVE-2018-0284 PUBLISHED CVSS 4 MEDIUM

A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.

EPSS 0.16% · 36.8th percentile

Risk Scores

CVSS 2.0
4
EPSS Score
0.16%
36.8th percentile

Affected Products

VendorProductVersions
ciscomeraki_mx_15_firmware0, 0, 0
ciscomeraki_mr_25_firmware0
ciscomeraki_mr_24_firmware0
CiscoCisco Meraki Z1<13.32
CiscoCisco Meraki M5<9.37
CiscoCisco Meraki MX<13.32
ciscomeraki_mx_14_firmware0, 0, 0
CiscoCisco Meraki Z3<13.32
ciscomeraki_ms_10_firmware0
CiscoCisco Meraki MR<24.13
ciscomeraki_ms_9_firmware0
ciscomeraki_mx_13_firmware0, 0, 0

Timeline

  • Nov 8, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›