CVE-2026-20115
EUVD-2026-1544725.03.2026, 16:16
A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this vulnerability by conducting an on-path attack between the affected device and the Cisco Meraki Dashboard. A successful exploit could allow the attacker to view sensitive device configuration information.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cisco | ios_xe | 17.14.1 |
| cisco | ios_xe | 17.14.1a |
| cisco | ios_xe | 17.15.1 |
| cisco | ios_xe | 17.15.1w |
| cisco | ios_xe | 17.15.1a |
| cisco | ios_xe | 17.15.2 |
| cisco | ios_xe | 17.15.1b |
| cisco | ios_xe | 17.15.1x |
| cisco | ios_xe | 17.15.1z |
| cisco | ios_xe | 17.15.3 |
| cisco | ios_xe | 17.15.2c |
| cisco | ios_xe | 17.15.2a |
| cisco | ios_xe | 17.15.1y |
| cisco | ios_xe | 17.15.2b |
| cisco | ios_xe | 17.15.3a |
| cisco | ios_xe | 17.15.4 |
| cisco | ios_xe | 17.15.3b |
| cisco | ios_xe | 17.15.4d |
| cisco | ios_xe | 17.15.4e |
| cisco | ios_xe | 17.16.1 |
| cisco | ios_xe | 17.16.1a |
| cisco | ios_xe | 17.17.1 |
| cisco | ios_xe | 17.18.1 |
| cisco | ios_xe | 17.18.1w |
| cisco | ios_xe | 17.18.1a |
𝑥
= Vulnerable software versions
Common Weakness Enumeration