Vulnerabilities > Cisco > Meraki MX Firmware

DATE CVE VULNERABILITY TITLE RISK
2014-12-24 CVE-2014-7999 Permissions, Privileges, and Access Controls vulnerability in Cisco products
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki defect ID 00478565.
low complexity
cisco CWE-264
7.7
2014-12-24 CVE-2014-7995 Permissions, Privileges, and Access Controls vulnerability in Cisco products
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's case and connecting a cable to a serial port, aka Cisco-Meraki defect ID 00302077.
local
low complexity
cisco CWE-264
7.2
2014-12-24 CVE-2014-7994 Improper Input Validation vulnerability in Cisco products
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the local network, aka Cisco-Meraki defect ID 00301991.
5.4
2014-12-24 CVE-2014-7993 Information Exposure vulnerability in Cisco products
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to obtain sensitive credential information by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki defect ID 00302012.
low complexity
cisco CWE-200
3.3