Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the local network, aka Cisco-Meraki defect ID 00301991.
2014-12-24T00:59:01.547
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.4 (MEDIUM)
AV:A/AC:M/Au:N/C:P/I:P/A:P
5.5
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | meraki_mr_firmware | ≤ 2014-09-24 | Yes |
Hardware | cisco | meraki_mr | - | Yes |
Application | cisco | meraki_mx_firmware | ≤ 2014-09-24 | Yes |
Hardware | cisco | meraki_mx | - | Yes |
Application | cisco | meraki_ms_firmware | ≤ 2014-09-24 | Yes |
Hardware | cisco | meraki_ms | - | Yes |