Cisco has issued software updates for a wide range of its Meraki networking products after an internal security review turned up multiple vulnerabilities, according to an advisory the company first published Oct. 7.
The company said the flaws were found by its own engineers during internal testing, which used existing processes along with frontier AI models. Cisco said it is not aware of any public disclosure or malicious use of the vulnerabilities.
Rather than issue one identifier per bug, Cisco sorted the findings into seven classes of weakness and assigned one CVE number to each class. The categories include access-control problems, memory buffer overflows, poor input validation, race conditions and similar control-flow errors, numeric calculation errors, and injection flaws. The most severe class carries a CVSS base score of 9.6 out of 10, which Cisco said reflects the single most serious underlying issue in that group.
The advisory covers Meraki Campus Gateways, MG cellular gateways, MR wireless access points, MS switches, MV smart cameras, and MX security and SD-WAN appliances. Cisco said there are no workarounds, so customers need to install fixed software.
Several fixes are already listed with release numbers, including MG version 26.1.4 and MR versions 30.7.3 and 31.1.8.1. Others are still on the way: Cisco lists a fix for Campus Gateway and MR software on the 32.2 branch for late October, MS switch release 18.1.9 for mid-October, and Campus Gateway release 33.1.4 for mid-November. The company updated the advisory on Oct. 8 to add a fixed release for older MX appliance software.