CVE-2026-20115
EUVD-2026-1544725.03.2026, 16:16
A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this vulnerability by conducting an on-path attack between the affected device and the Cisco Meraki Dashboard. A successful exploit could allow the attacker to view sensitive device configuration information.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| cisco | ios_xe | 17.14.1 | CNA |
| cisco | ios_xe | 17.14.1a | CNA |
| cisco | ios_xe | 17.15.1 | CNA |
| cisco | ios_xe | 17.15.1w | CNA |
| cisco | ios_xe | 17.15.1a | CNA |
| cisco | ios_xe | 17.15.2 | CNA |
| cisco | ios_xe | 17.15.1b | CNA |
| cisco | ios_xe | 17.15.1x | CNA |
| cisco | ios_xe | 17.15.1z | CNA |
| cisco | ios_xe | 17.15.3 | CNA |
| cisco | ios_xe | 17.15.2c | CNA |
| cisco | ios_xe | 17.15.2a | CNA |
| cisco | ios_xe | 17.15.1y | CNA |
| cisco | ios_xe | 17.15.2b | CNA |
| cisco | ios_xe | 17.15.3a | CNA |
| cisco | ios_xe | 17.15.4 | CNA |
| cisco | ios_xe | 17.15.3b | CNA |
| cisco | ios_xe | 17.15.4d | CNA |
| cisco | ios_xe | 17.15.4e | CNA |
| cisco | ios_xe | 17.16.1 | CNA |
| cisco | ios_xe | 17.16.1a | CNA |
| cisco | ios_xe | 17.17.1 | CNA |
| cisco | ios_xe | 17.18.1 | CNA |
| cisco | ios_xe | 17.18.1w | CNA |
| cisco | ios_xe | 17.18.1a | CNA |
Common Weakness Enumeration