CVE-2019-1815 Details
Description
A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security appliance models that may allow unauthenticated individuals to access and download logs containing sensitive, privileged device information. The vulnerability is due to improper access control to the files holding debugging and maintenance information, and is only exploitable when the local status page is enabled on the device. An attacker exploiting this vulnerability may obtain access to wireless pre-shared keys, Site-to-Site VPN key and other sensitive information. Under certain circumstances, this information may allow an attacker to obtain administrative-level access to the device.
A vulnerability exists in the local status page feature of Cisco Meraki MX67 and MX68 security appliances. This issue may enable unauthenticated users to access and download logs containing sensitive device information. The vulnerability arises from inadequate access controls on files that store debugging and maintenance data, and can only be exploited if the local status page is activated on the device. An attacker could potentially retrieve wireless pre-shared keys, Site-to-Site VPN keys, and other confidential information, which might lead to administrative access on the device under certain conditions.
Users are advised to schedule a firmware upgrade to version 14.39 or later for the MX67 model and version 15.12 or later for the MX68 model. Additionally, the local status page can be disabled manually or via the Dashboard API. After upgrading the firmware, it is recommended to change all passwords and secrets used with the MX devices for certain features, such as Site-to-Site VPN or Active Directory integrations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 4, 2025CISA-ADP
Assessed Mar 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cisco Meraki MX67 | All versions |
CPE
Remediation
| |
| Cisco Meraki MX68 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2025 | New CVE Received | [email protected] |
Volerion