#VU15772 Privilege escalation in Cisco Systems, Inc products - CVE-2018-0284
Published: November 7, 2018 / Updated: November 8, 2018
Meraki Z3
Meraki Z1
Meraki MX
Meraki MS
Meraki MR
Cisco Systems, Inc
Description
The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.
The vulnerability exists in the local status page functionality due to an error when handling requests to the local status page. A remote unauthenticated attacker can establish an interactive session, gain elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.
Remediation
Update Meraki MS to version 9.37, 10.20.
Update Meraki MX to version 14.25, 15.7.
Update Meraki Z1 to version 14.25, 15.7.
Update Meraki Z3 to version 14.25, 15.7.