CNNVD-202506-2548 Information

CNNVD ID

CNNVD-202506-2548

CVE-2025-20271

  • CNNVD Published: 2025-06-18

Description (Chinese)

Cisco Meraki Z和Cisco Meraki MX都是美国思科(Cisco)公司的产品。Cisco Meraki Z是一款企业级防火墙、VPN 网关和路由器。Cisco Meraki MX是一款多功能安全和 SD-WAN 企业设备。 Cisco Meraki Z和Cisco Meraki MX存在安全漏洞,该漏洞源于SSL VPN会话建立期间变量初始化错误,可能导致拒绝服务攻击。

Description (English)

Cisco Meraki Z and Cisco Meraki MX are all Cisco products. Cisco Meraki Z is an enterprise-level firewall, a VPN gateway and router. Cisco Meraki MX is a multifunctional security and SD-WAN enterprise equipment. Cisco Meraki Z and Cisco Meraki MX had a security loophole, which stemmed from an initialization error of the variable during the SSL VPN session and could lead to a denial of service attack.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

思科

Published

2025-06-18

Last Modified

2026-02-24

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-meraki-mx-vpn-dos-sM5GCfm7 https://vigilance.fr/vulnerability/Cisco-Meraki-MX-denial-of-service-via-Cisco-AnyConnect-VPN-Server-47480

Patch

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-meraki-mx-vpn-dos-sM5GCfm7

Share on: