Cisco Meraki has released free software updates that address the vulnerability that is described in this advisory. Cisco Meraki recommends that customers upgrade to a fixed release.
Customers may only install and expect support for software releases and feature sets for which they have purchased a license. By installing, downloading, accessing, or otherwise using such software upgrades, customers agree to follow the terms of the Cisco End User License Agreement and applicable Product Specific Terms:
https://www.cisco.com/c/en/us/products/end-user-license-agreement.html
Additionally, customers may only download software for which they have a valid license, procured from Cisco Meraki directly, or through a Cisco Meraki authorized reseller or partner. In most cases, this will be a maintenance upgrade to software that was previously purchased. Free security software updates do not entitle customers to a new software license, additional software feature sets, or major revision upgrades.
Customers are advised to regularly consult the advisories for Cisco Meraki products, which are available from the Cisco Security Advisories page, to determine exposure and a complete upgrade solution.
In all cases, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. Cisco Meraki recommends utilizing firmware best practices for firmware updates. If the information is not clear, customers are advised to contact Cisco Meraki Support.
Fixed Releases
At the time of publication, the release information in the following table was accurate. Cisco Meraki will update this advisory as required.
In the following table, the left column lists Cisco Meraki firmware releases. The right column indicates whether a release is affected by the vulnerability that is described in this advisory and the first release that includes the fix for this vulnerability. Customers are advised to upgrade to an appropriate fixed software release as indicated in this section.
Cisco Meraki MX Firmware Release |
First Fixed Release |
Earlier than 16.2 |
Not affected. |
16.2 |
Migrate to a fixed release. |
17 |
Migrate to a fixed release. |
18.1xx |
18.107.13 |
18.2xx |
18.211.6 |
19.1 |
19.1.8 |
Notes:
- Cisco Meraki MX64 and MX65 are affected only when they are running Cisco Meraki MX firmware releases 17.6 and later.
- Cisco Meraki MX400 and MX600 support only firmware releases 16.16.9 and earlier. These models have entered the end-of-life process and will not receive a fix for this vulnerability.
The Cisco Product Security Incident Response Team (PSIRT) validates only the affected and fixed release information that is documented in this advisory.