Cisco Meraki Mx Firmware vulnerabilities

11 known vulnerabilities affecting cisco/cisco_meraki_mx_firmware.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2025-20271HIGHCVSS 8.6vN/A2025-06-18
CVE-2025-20271 [HIGH] CWE-457 CVE-2025-20271: A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Tele A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. This vulnerability is due to variable initialization errors when an SSL VPN sessi
cvelistv5nvd
CVE-2025-20212HIGHCVSS 7.7v16.2v16.3+12 more2025-04-02
CVE-2025-20212 [HIGH] CWE-457 CVE-2025-20212: A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devi A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. To exploit this vulnerability, the attacker must have valid VPN user credentials on the affected device
cvelistv5nvd
CVE-2019-1815MEDIUMCVSS 5.3vN/A2025-03-04
CVE-2019-1815 [MEDIUM] CWE-200 CVE-2019-1815: A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX6 A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security appliance models that may allow unauthenticated individuals to access and download logs containing sensitive, privileged device information. The vulnerability is due to improper access control to the files holding debugging and maint
cvelistv5nvd
CVE-2024-20498HIGHCVSS 7.5vN/A2024-10-02
CVE-2024-20498 [HIGH] CWE-415 CVE-2024-20498: Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Se Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of client-supplied parameters while estab
cvelistv5nvd
CVE-2024-20501HIGHCVSS 7.5vN/A2024-10-02
CVE-2024-20501 [HIGH] CWE-787 CVE-2024-20501: Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Se Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of client-supplied parameters while estab
cvelistv5nvd
CVE-2024-20500HIGHCVSS 7.5vN/A2024-10-02
CVE-2024-20500 [MEDIUM] CWE-400 CVE-2024-20500: A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Tele A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. This vulnerability is due to insufficient resource management when establishing TLS/SSL sessions. An atta
cvelistv5nvd
CVE-2024-20499HIGHCVSS 7.5vN/A2024-10-02
CVE-2024-20499 [HIGH] CWE-787 CVE-2024-20499: Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Se Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. These vulnerabilities are due to insufficient validation of client-supplied parameters while estab
cvelistv5nvd
CVE-2024-20502HIGHCVSS 7.5vN/A2024-10-02
CVE-2024-20502 [MEDIUM] CWE-400 CVE-2024-20502: A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Tele A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to insufficient resource management while establishing SSL VPN sessions. An attacker could exploit this v
cvelistv5nvd
CVE-2024-20513MEDIUMCVSS 5.3vN/A2024-10-02
CVE-2024-20513 [MEDIUM] CWE-639 CVE-2024-20513: A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Tele A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition for targeted users of the AnyConnect service on an affected device. This vulnerability is due to insufficient entropy for handlers that are used during SS
cvelistv5nvd
CVE-2024-20509MEDIUMCVSS 5.9v-16-2v-16-3+9 more2024-10-02
CVE-2024-20509 [MEDIUM] CWE-362 CVE-2024-20509: A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Tele A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to hijack an AnyConnect VPN session or cause a denial of service (DoS) condition for individual users of the AnyConnect VPN service on an affected device. This vulnerability is due
cvelistv5nvd
CVE-2022-20933HIGHCVSS 8.6vn/a2022-10-26
CVE-2022-20933 [HIGH] CWE-234 CVE-2022-20933: A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of client-supplied parameters while establishing an SSL VPN session
cvelistv5nvd