CVE-2018-0284 - CVE House
Back to Database
Status published Medium CVE-2018-0284

Cisco Meraki Local Status Page Privilege Escalation Vulnerability

Vulnerability Description

A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-0284

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco Meraki MR, Cisco Meraki M5, Cisco Meraki MX, Cisco Meraki Z1, Cisco Meraki Z3
Vulnerable Versions:
<24.13, <9.37, <13.32

Timeline

Official Publish: November 8th, 2018
Last Modified: November 26th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Weaknesses (CWE)