Privilege Escalation Vulnerability (11-13-17)

CameronMoody
Meraki Employee
Meraki Employee

Privilege Escalation Vulnerability (11-13-17)

On October 18, 2017, Cisco Meraki corrected a technical error in the Meraki dashboard that made sensitive administrator authentication information available to other trusted dashboard users within the same organization. The issue allowed trusted users, with varying levels of permission, to view and access the API key and encrypted (BCrypt hashed and salted) passwords for their organization’s primary administrator. 

 

For more information on this issue and how Meraki has resolved this vulnerability, please refer to this article.

 

Cameron Moody | Product Manager, Cisco Meraki
0 Replies 0
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.