{"id":"8b2463ab-810e-4557-ae0c-b91b9c9ec379","engagementId":"b8d0f9a9-52d4-4e2e-8775-12adf4b5c597","data":{"brief":{"id":"39bdb727-a95e-4753-b56c-891e47d7508a","name":"Cisco Networking","tagline":"Agentic operations, custom silicon, and integrated security—engineered for the way enterprises connect and operate today.","description":"\u003cp\u003eThe security of our customers is a top priority. We invest heavily in tools, processes and technologies to keep our users and their networks safe. This includes third-party audits, features like two-factor authentication, and our out-of-band cloud management architecture. The Cisco Networking vulnerability rewards program is an important component of our overall security strategy, encouraging external researchers to collaborate with our security team to help keep our customers safe.\u003c/p\u003e\n\n\u003cp\u003eBe sure to watch for new releases on the Cisco \u003ca href=\"https://developer.cisco.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDeveloper Portal\u003c/a\u003e!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWe are specifically looking for high-impact vulnerabilities that affect the security and integrity of our platform and products. While we welcome all valid security reports, we are currently prioritizing the following areas:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eInsecure Direct Object Reference (IDOR): Vulnerabilities that allow unauthorized access to objects, data, or settings.\u003c/li\u003e\n\u003cli\u003ePrivilege Escalation: Flaws that allow a user to gain higher-level permissions (vertical or horizontal escalation).\u003c/li\u003e\n\u003cli\u003eRemote code execution as root\u003c/li\u003e\n\u003cli\u003eRemote root login\u003c/li\u003e\n\u003cli\u003eRemote configuration injections\u003c/li\u003e\n\u003cli\u003eDirect exposure of highly sensitive customer data to unauthorized parties sourced from the Meraki platform, for example, when Cisco or a Cisco employee is responsible for the exposure. This includes:\n\n\u003cul\u003e\n\u003cli\u003eDevice secrets\u003c/li\u003e\n\u003cli\u003eCryptographic keys\u003c/li\u003e\n\u003cli\u003eMV camera footage\u003c/li\u003e\n\u003cli\u003eCustomer credentials or PII\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eFull compromise of secure boot\u003c/li\u003e\n\u003cli\u003e\"Packet of death\" or similar mass Denial of Service\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"d7a636ff-c862-4101-a74f-f556036a5772","targetsOverview":"\u003cp\u003e\u003cem\u003eAny domain/property of Cisco not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials and Access\u003c/h2\u003e\n\n\u003ch3\u003eMeraki Dashboard Cloud Platform\u003c/h3\u003e\n\n\u003cp\u003eCreate a user account at \u003ca href=\"https://meraki.cisco.com/form/demo\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://meraki.cisco.com/form/demo\u003c/a\u003e, using your @bugcrowdninja.com email address. This will provide you with access to a demo organization and user account. To create a 2nd user-account within this demo organization, navigate to the \"Organization\" tab (left sidebar) and select \"Administrators\". \u003c/p\u003e\n\n\u003cp\u003eWe recommend creating two (2) demo organizations to test cross-account permissions and access. Please use a \"+\" variation of your @bugcrowdninja.com email address (example: user+1@bugcrowdninja.com - for more information on @bugcrowdninja emails, see here: \u003ca href=\"https://researcherdocs.bugcrowd.com/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://researcherdocs.bugcrowd.com/docs/your-bugcrowdninja-email-address\u003c/a\u003e).\u003c/p\u003e\n\n\u003ch2\u003eOut of Scope Attacks\u003c/h2\u003e\n\n\u003cp\u003eThe following attacks are excluded from the scope of our bug bounty program:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFirmware/component findings without demonstrated product impact, including reports based only on extracted components, standalone binaries, open-source packages, libraries, emulated services, or test harnesses. \u003c/li\u003e\n\u003cli\u003eReports that only identify a vulnerable package version, CVE, unsafe function, crash, static-analysis result, fuzzing result, emulated behavior, test-harness result, or theoretical weakness without showing reachability, exploitability, and security impact in an in-scope product. \u003c/li\u003e\n\u003cli\u003eFindings that depend on non-shipped configurations, debug or modified builds, disabled features, dead code, manually invoked internal paths, or an already-privileged state, unless the report demonstrates how an attacker can reach that condition on production hardware or through a supported customer-accessible configuration. \u003c/li\u003e\n\u003cli\u003eExposure of customer credentials where Cisco is not directly responsible for the exposure.\nExamples include, but are not limited to: credentials leaked due to customer or environment misconfigurations, breaches of third-party systems, data discovered on external data brokerage sites, or any incidents occurring outside of Cisco’s listed in-scope infrastructure or control.\u003c/li\u003e\n\u003cli\u003eSubdomain takeover\u003c/li\u003e\n\u003cli\u003eAdobe Marketo tokens\u003c/li\u003e\n\u003cli\u003eEmail bombing/flooding attack\u003c/li\u003e\n\u003cli\u003eDeficiencies in a security feature in an on-prem product. For example, 802.1x multi auth vs multi-host on MX and MS\u003c/li\u003e\n\u003cli\u003eFlaws present only when using out-of-date browsers or plugins\n\n\u003cul\u003e\n\u003cli\u003eOnly current versions of Chrome, Firefox, IE, Edge are accepted\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSelf XSS, except novel attacks\u003c/li\u003e\n\u003cli\u003eText injection\u003c/li\u003e\n\u003cli\u003eEmail spoofing and any form of social engineering attack\u003c/li\u003e\n\u003cli\u003eFull or partial path disclosure except when a real security impact can be demonstrated\u003c/li\u003e\n\u003cli\u003eMissing Secure or HTTPOnly flags on cookies, except for these sensitive cookies:\n\n\u003cul\u003e\n\u003cli\u003edash_auth_token\u003c/li\u003e\n\u003cli\u003edash_auth\u003c/li\u003e\n\u003cli\u003edevel_dash_auth\u003c/li\u003e\n\u003cli\u003etwo_factor_auth\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced, unless it is configured in one or more of the user's organizations\u003c/li\u003e\n\u003cli\u003eURL redirection\u003c/li\u003e\n\u003cli\u003eAttacks by an administrator that affect the organization’s own users (e.g. malicious custom splash pages)\u003c/li\u003e\n\u003cli\u003eAny attack against Cisco corporate infrastructure\u003c/li\u003e\n\u003cli\u003eDiscovery of any in-use service whose running version includes known vulnerabilities without demonstrating an exploit\u003c/li\u003e\n\u003cli\u003eEnumeration: brute force testing any of the below for enumeration each require separate advanced notification and permission from the Cisco Networking Security Organization prior to testing. Any report which comes from unauthorized testing will be considered out of scope.\n\n\u003cul\u003e\n\u003cli\u003eUsername\u003c/li\u003e\n\u003cli\u003eEmail\u003c/li\u003e\n\u003cli\u003eOrder Number\u003c/li\u003e\n\u003cli\u003eSerial Number\u003c/li\u003e\n\u003cli\u003eLicense Key Enumeration issues will generally not be in scope but for exceptional cases, e.g. ability to enumerate email addresses via incrementing a parameter.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAll brute force denial-of-service attacks\u003c/li\u003e\n\u003cli\u003eSSL/TLS attacks\u003c/li\u003e\n\u003cli\u003eAny attack which renders the device permanently inoperable\u003c/li\u003e\n\u003cli\u003eMultifactor bypass for users who are already authenticated.\u003c/li\u003e\n\u003cli\u003eAny attack exploitable only by an active Man in the Middle. Any XSS exploitable only by an active Man in the Middle\u003c/li\u003e\n\u003cli\u003eReflected downloads\u003c/li\u003e\n\u003cli\u003eAny hardware bugs which require a debugger to recreate\u003c/li\u003e\n\u003cli\u003eVulnerabilities in open source packages less than one month old\u003c/li\u003e\n\u003cli\u003eAny vulnerability not present in the most recent beta firmware of a product\u003c/li\u003e\n\u003cli\u003eFeature deficiencies are excluded, for example:\n\n\u003cul\u003e\n\u003cli\u003eMissing security features (e.g. SSL/TLS on the Local Status Page), except where novel attacks can be demonstrated\u003c/li\u003e\n\u003cli\u003eBypass of Advanced Security functionality (e.g. AMP, Content Filtering) on the MX\u003c/li\u003e\n\u003cli\u003eBypass of URL blacklists on any platform\u003c/li\u003e\n\u003cli\u003eGroup Policy/Splash Policy bypass on all platforms, this includes firewall rule bypass in the presence of group policies\u003c/li\u003e\n\u003cli\u003eIf you are unsure if this exclusion applies, please ask.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities resulting from missing or altered public-key pins\u003c/li\u003e\n\u003cli\u003eDLL injection for mobile apps\u003c/li\u003e\n\u003cli\u003eBeing able to enroll in a Systems Manager deployment that has enrollment authentication disabled\u003c/li\u003e\n\u003cli\u003eIf the root cause of a vulnerability affects multiple different endpoints, we treat it as one submission and mark reports that exploit the same vulnerability at the multiple endpoints as duplicates.\u003c/li\u003e\n\u003cli\u003eCustomer API keys which are used by a Cisco end user to interact with Cisco services are out of scope. \u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":"\u003ch2\u003eLegal Information\u003c/h2\u003e\n\n\u003cp\u003eIn addition to these Terms and Conditions regarding the Cisco Networking Bugcrowd Program (“the Program”), there may be additional restrictions depending upon applicable local laws.\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003e The parties to this Agreement are you and Cisco  Networking.\u003c/li\u003e\n\u003cli\u003e \"Cisco  Networking\" refers to  Cisco Systems, Inc.\u003c/li\u003e\n\u003cli\u003e By participating in the Program, investigating a potential vulnerability, or submitting a vulnerability, you affirm that you have not disclosed and agree that you will not disclose the vulnerability to anyone other than Cisco  Networking. Absent Cisco  Networking’s prior written consent, any disclosure outside of this process would violate this Agreement. You agree that money damages may not be a sufficient remedy for a breach of this paragraph by you, and that Cisco Networking will be entitled to specific performance as a remedy for any such breach. Such remedy will not be deemed to be the exclusive remedy for any such breach but will be in addition to all other remedies available at law or equity to Cisco  Networking.\u003c/li\u003e\n\u003cli\u003e By submitting information about a potential vulnerability, you are granting Cisco  Networking a worldwide, royalty-free, non-exclusive license to use your submission for the purpose of addressing vulnerabilities in Cisco  Networking’s products and services.\u003c/li\u003e\n\u003cli\u003e In the event of substantially duplicate submissions, Cisco  Networking may at its discretion provide a reward only for the earliest received submission. Eligibility for rewards, determination of the recipients, and amount of reward is at the discretion of Cisco  Networking.\u003c/li\u003e\n\u003cli\u003e If issues reported to the Program  affect a third party or another vendor, Cisco  Networking reserves the right to forward details of the issue along to the party without further discussion with the researcher.\u003c/li\u003e\n\u003cli\u003e You are responsible for all taxes associated with and imposed on any reward you may receive from Cisco  Networking.\u003c/li\u003e\n\u003cli\u003e You may only exploit, investigate, or target vulnerabilities against your own accounts and/or your own devices. Testing must not violate any law, or disrupt or compromise any data or access data that is not yours; intentional access of customer data other than your own is prohibited.\u003c/li\u003e\n\u003cli\u003e If you inadvertently access proprietary customer, employee, or business-related information during your testing, the information must not be used, disclosed, stored, or recorded in any way. In the event of inadvertent access to such data, you must delete such data immediately and notify Cisco  Networking of such inadvertent access within your submission.\u003c/li\u003e\n\u003cli\u003eYour testing activities must not negatively impact Cisco  Networking, Cisco  Networking’s products or services generally, or Cisco  Networking’s online environment availability or performance. Cisco  Networking may choose not to remediate at its sole discretion.\u003c/li\u003e\n\u003cli\u003eThis Agreement constitutes the entire agreement of the parties with respect to the items listed above. This Agreement is covered by California law. This Agreement may be amended or modified only by a subsequent agreement in writing.\u003c/li\u003e\n\u003cli\u003eIf any portion of this Agreement is found to be illegal or unenforceable, then the parties will be relieved of their responsibilities arising under such portion, but only to the extent that such portion is illegal or unenforceable.\u003c/li\u003e\n\u003cli\u003eYou must not be the author of the code with the vulnerability.\u003c/li\u003e\n\u003cli\u003eYou must not be an employee or contractor of Cisco  Networking or its affiliates, or a family member of an employee or contractor.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eCISCO  NETWORKING RESERVES THE RIGHT TO MODIFY OR CANCEL THIS PROGRAM AT ANY TIME WITHOUT NOTICE. ALL PARTICIPANTS AND SUBMISSIONS ARE STRICTLY VOLUNTARY. THIS OFFER IS VOID WHERE PROHIBITED BY LAW AND IN PARTICIPATING, YOU MUST NOT VIOLATE ANY LAW. YOU ALSO MUST NOT DISRUPT ANY SERVICE OR COMPROMISE ANYONE’S DATA.\u003c/p\u003e"},"scope":[{"id":"93a18bca-8a03-4b0f-aabc-0f5d5aea10ae","name":"Cisco Meraki Dashboard Platform Targets","targets":[{"id":"8ace220c-2c6e-4007-8e7e-7df59c4f6c70","uri":null,"name":"*.meraki.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"785bd10a-79ad-483d-a810-dd307f43e710","sortOrder":0},"sortOrder":0,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"8ace220c-2c6e-4007-8e7e-7df59c4f6c70"},{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"8ace220c-2c6e-4007-8e7e-7df59c4f6c70"},{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"8ace220c-2c6e-4007-8e7e-7df59c4f6c70"},{"id":"5a702681-f59c-463c-b266-f9e22a1e1d8a","name":"Scala","targetId":"8ace220c-2c6e-4007-8e7e-7df59c4f6c70"},{"id":"6481be19-8d64-4bb2-8426-2f1f7afe32e6","name":"Modernizr","targetId":"8ace220c-2c6e-4007-8e7e-7df59c4f6c70"},{"id":"9558d6b3-9880-4506-9e19-55dc1d7d8aff","name":"RequireJS","targetId":"8ace220c-2c6e-4007-8e7e-7df59c4f6c70"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"8ace220c-2c6e-4007-8e7e-7df59c4f6c70"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8ace220c-2c6e-4007-8e7e-7df59c4f6c70"}],"recentChangeFlags":null},{"id":"ea5f4d37-7638-4ec7-b9a5-43754c617232","uri":null,"name":"*.ikarem.io","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8285c0d6-6d9d-4782-a655-9f9afd7e48e8","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ea5f4d37-7638-4ec7-b9a5-43754c617232"}],"recentChangeFlags":null},{"id":"76a015b0-6444-47c5-8754-e1eaee722a15","uri":null,"name":"Cisco Meraki Systems Manager","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"69efe0d5-e910-4536-869a-877d2dcd2809","sortOrder":0},"sortOrder":0,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"76a015b0-6444-47c5-8754-e1eaee722a15"},{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"76a015b0-6444-47c5-8754-e1eaee722a15"},{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"76a015b0-6444-47c5-8754-e1eaee722a15"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"76a015b0-6444-47c5-8754-e1eaee722a15"},{"id":"c5df6ad0-33b4-40ac-b6dd-8d4038997d40","name":"macOS","targetId":"76a015b0-6444-47c5-8754-e1eaee722a15"},{"id":"fc8162a2-8e37-4a27-8cbd-3b40e7799f4e","name":"Desktop Application Testing","targetId":"76a015b0-6444-47c5-8754-e1eaee722a15"}],"recentChangeFlags":null},{"id":"52ee9d3e-b632-4fde-98d0-dab6bda991aa","uri":null,"name":"*.network-auth.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3fb07b77-6539-46db-b25d-54e81f6cc05e","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"52ee9d3e-b632-4fde-98d0-dab6bda991aa"}],"recentChangeFlags":null},{"id":"754e3961-7373-4be1-b9a7-0d95d865bb1f","uri":null,"name":"Cisco Meraki Dashboard Mobile Application (iOS and Android)","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1603094e-82e3-4007-89d4-c82c545b44da","sortOrder":0},"sortOrder":0,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"754e3961-7373-4be1-b9a7-0d95d865bb1f"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"754e3961-7373-4be1-b9a7-0d95d865bb1f"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"754e3961-7373-4be1-b9a7-0d95d865bb1f"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"25d0fc8d-7a8e-40a9-b128-7e9b3ab6713b","p1MaxCents":1000000,"p1MinCents":600000,"p2MaxCents":600000,"p2MinCents":250000,"p3MaxCents":250000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eBy way of clarification, the following is additional information on some of the domains that are in scope, and details around how they are used:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e*.ikarem.io: This domain is used for Meraki internal services, and as such, falls under the higher reward range.\u003c/li\u003e\n\u003cli\u003e*.meraki.com: This domain is for the Cisco Meraki Dashboard and its integrated services.\u003c/li\u003e\n\u003cli\u003e*.network-auth.com: This domain hosts user-created content for Dashboard-configured splash pages.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eFurther public documentation can be found at \u003ca href=\"https://documentation.meraki.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://documentation.meraki.com\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eAdditionally, documentation for the Cisco Meraki Dashboard API can be found at \u003ca href=\"https://create.meraki.io/api-docs/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://create.meraki.io/api-docs/\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eIt\u0026#39;s further worth noting that:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eMost products run a light web server which offers the ability to locally configure the uplink of a device, as well as to see some very basic device status information. However, the Dashboard is the ultimate administrative interface for devices, as well as the primary source for device monitoring.\u003c/li\u003e\n\u003cli\u003eThis is touched on in the focus areas section, but any way of obtaining shell access on a Meraki device is an interesting finding to our team — as there should be no way for a user to meaningfully authenticate to a device.\u003c/li\u003e\n\u003cli\u003eIn regards to obtaining firmware images, users may configure, via the Dashboard, a firmware version for a device to run and the device will automatically download and install the new version. More information on that can be found in our firmware FAQ.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":6000,"max":10000},"2":{"min":2500,"max":6000},"3":{"min":500,"max":2500},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"ffcdfaaf-4311-4668-80c5-23f4b789bfed","name":"Cisco Meraki Devices (Hardware \u0026 Firmware)","targets":[{"id":"74b2e717-759f-4142-a008-7c34efcac151","uri":"","name":"Cisco Campus Gateways","category":"hardware","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9cae5b2b-7753-4ab0-8477-ff7fc6c05dfd","sortOrder":0},"sortOrder":0,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"74b2e717-759f-4142-a008-7c34efcac151"},{"id":"4cb84232-a78c-4fc6-b51e-cbe67d4ee5f1","name":"IoT","targetId":"74b2e717-759f-4142-a008-7c34efcac151"},{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"74b2e717-759f-4142-a008-7c34efcac151"}],"recentChangeFlags":null},{"id":"9975ef27-85ac-47a0-9d57-c9820f1e3f05","uri":"","name":"Cisco Catalyst 9200L Series Switches (Cloud-Managed)","category":"hardware","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d883c37d-21cf-47e3-84fd-07e6537abff4","sortOrder":1},"sortOrder":1,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"9975ef27-85ac-47a0-9d57-c9820f1e3f05"},{"id":"4cb84232-a78c-4fc6-b51e-cbe67d4ee5f1","name":"IoT","targetId":"9975ef27-85ac-47a0-9d57-c9820f1e3f05"},{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"9975ef27-85ac-47a0-9d57-c9820f1e3f05"}],"recentChangeFlags":null},{"id":"adbfee76-991c-4e8a-aa0c-c45f16768baa","uri":null,"name":"Cisco Meraki MX \u0026 Z Series Security Appliances (Including vMX)","category":"hardware","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"79bef09a-f767-4af0-a1bc-a017b4fca901","sortOrder":2},"sortOrder":2,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"adbfee76-991c-4e8a-aa0c-c45f16768baa"},{"id":"4cb84232-a78c-4fc6-b51e-cbe67d4ee5f1","name":"IoT","targetId":"adbfee76-991c-4e8a-aa0c-c45f16768baa"},{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"adbfee76-991c-4e8a-aa0c-c45f16768baa"}],"recentChangeFlags":null},{"id":"bc17443f-a07f-4fc8-b11d-0e46650ef8dc","uri":null,"name":"Cisco Meraki MS Switches","category":"hardware","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"11498ae7-95b8-471a-bc43-e3e3c7c92c60","sortOrder":3},"sortOrder":3,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"bc17443f-a07f-4fc8-b11d-0e46650ef8dc"},{"id":"4cb84232-a78c-4fc6-b51e-cbe67d4ee5f1","name":"IoT","targetId":"bc17443f-a07f-4fc8-b11d-0e46650ef8dc"},{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"bc17443f-a07f-4fc8-b11d-0e46650ef8dc"}],"recentChangeFlags":null},{"id":"30ff39f7-ca40-45ab-ab61-fc406302fd4b","uri":null,"name":"Cisco Meraki MR Access Points","category":"hardware","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"75cf47d3-61ee-463a-bc15-597b18a4ce8c","sortOrder":4},"sortOrder":4,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"30ff39f7-ca40-45ab-ab61-fc406302fd4b"},{"id":"4cb84232-a78c-4fc6-b51e-cbe67d4ee5f1","name":"IoT","targetId":"30ff39f7-ca40-45ab-ab61-fc406302fd4b"},{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"30ff39f7-ca40-45ab-ab61-fc406302fd4b"}],"recentChangeFlags":null},{"id":"af8392b3-151a-4816-9ede-8c26adb587b6","uri":null,"name":"Cisco Meraki MV Smart Cameras","category":"hardware","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"69553c44-f184-4a14-805e-04642d842af7","sortOrder":5},"sortOrder":5,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"af8392b3-151a-4816-9ede-8c26adb587b6"},{"id":"4cb84232-a78c-4fc6-b51e-cbe67d4ee5f1","name":"IoT","targetId":"af8392b3-151a-4816-9ede-8c26adb587b6"},{"id":"d7febc58-1d4d-4c69-9777-5d473211ddb4","name":"Surveillance and Security","targetId":"af8392b3-151a-4816-9ede-8c26adb587b6"},{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"af8392b3-151a-4816-9ede-8c26adb587b6"}],"recentChangeFlags":null},{"id":"3194e2ce-2a50-4c74-9594-2f05d3acd45b","uri":"","name":"Cisco Meraki MG Fixed Wireless Access Devices","category":"hardware","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"51f5f7fb-2785-470e-9ce3-948e3262f6d1","sortOrder":6},"sortOrder":6,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"3194e2ce-2a50-4c74-9594-2f05d3acd45b"},{"id":"4cb84232-a78c-4fc6-b51e-cbe67d4ee5f1","name":"IoT","targetId":"3194e2ce-2a50-4c74-9594-2f05d3acd45b"},{"id":"ee6e7cc3-455d-4d97-b43e-5b8de420d096","name":"Hardware Testing","targetId":"3194e2ce-2a50-4c74-9594-2f05d3acd45b"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"25d0fc8d-7a8e-40a9-b128-7e9b3ab6713b","p1MaxCents":1000000,"p1MinCents":600000,"p2MaxCents":600000,"p2MinCents":250000,"p3MaxCents":250000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eWe welcome research into in-scope hardware, virtual devices such as Cisco Meraki vMX, device firmware, bootloaders, services, libraries, open-source packages, and other shipped components. Component-level analysis is valuable supporting evidence when it helps identify reachable security issues in shipped products. \u003c/p\u003e\n\n\u003ch3\u003eEligibility Requirements\u003c/h3\u003e\n\n\u003cp\u003eReports must demonstrate product-relevant security impact on an in-scope product in a real-world or production-equivalent context. \u003c/p\u003e\n\n\u003cp\u003eStrong reports should include: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eaffected in-scope product and firmware/software version; \u003c/li\u003e\n\u003cli\u003eaffected component, package, binary, code path, or boot path; \u003c/li\u003e\n\u003cli\u003eattacker position and prerequisites; \u003c/li\u003e\n\u003cli\u003ereachable input or execution path in the product; \u003c/li\u003e\n\u003cli\u003econcrete security impact; \u003c/li\u003e\n\u003cli\u003ereproduction steps on real hardware or in a production-equivalent environment, or a clear explanation of why equivalent evidence is sufficient. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eWe encourage researchers to submit well-supported work even when a full exploit is difficult, provided the report clearly separates what has been confirmed on an in-scope product from what is inferred from component-level analysis. When full exploitation is not practical, please provide the strongest evidence available and explain what would be needed to complete validation. \u003c/p\u003e\n\n\u003ch3\u003eFirmware and Component Reachability\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eComponent-level evidence, such as reverse engineering, static or dynamic analysis, emulation, fuzzing, extracted component testing, debugger output, or test harnesses, is useful supporting evidence. However, it is not sufficient by itself for bounty eligibility unless the report maps the issue to reachable, exploitable behavior in an in-scope product. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eReports should explain how attacker-controlled input or execution reaches the affected code path and how the issue affects confidentiality, integrity, availability, product trust, or customer security posture. If real hardware reproduction is not provided, explain why the evidence is production-equivalent for the claimed impact, such as matching shipped firmware, configuration, exposed paths, and runtime mitigations. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eFindings that depend on privileged, debug, modified, or non-default states should explain how an attacker obtains that state on production hardware or through a supported customer-accessible configuration. These states are usually prerequisites rather than security impact by themselves, unless the report demonstrates a separate real-world attack path. \u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eHardware Notes\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eShell Access: Any method of obtaining shell access on a Cisco Meraki device is considered a high-priority finding, as there should be no mechanism for a user to meaningfully authenticate to a device.\u003c/li\u003e\n\u003cli\u003eFirmware Images: Researchers may configure a specific firmware version for a device to run via the Dashboard, which will trigger the device to automatically download and install the selected version. For more details, please refer to our firmware FAQ.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":6000,"max":10000},"2":{"min":2500,"max":6000},"3":{"min":500,"max":2500},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"d6422ee2-9423-4564-afbe-8fde71ccdddf","name":"Out of Scope","targets":[{"id":"14380eaa-67f1-4ebd-8424-bb0257638952","uri":null,"name":"merakipartners.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"612c2e8f-a60b-4308-8ff4-e641dcdee39f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"14380eaa-67f1-4ebd-8424-bb0257638952"}],"recentChangeFlags":null},{"id":"bb3f1a25-d673-4356-a490-f5d95c59ab3b","uri":null,"name":"developers.meraki.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"04319197-df27-4b09-b07b-6cca297f9022","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"bb3f1a25-d673-4356-a490-f5d95c59ab3b"}],"recentChangeFlags":null},{"id":"8a6ca829-d1b4-4dc2-9b9e-63ce42b94ec3","uri":null,"name":"smhelp.meraki.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"35e5c00f-974a-400f-8e2d-95f07b703281","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8a6ca829-d1b4-4dc2-9b9e-63ce42b94ec3"}],"recentChangeFlags":null},{"id":"70bdfd14-d8fe-4e98-840c-d0b303985916","uri":null,"name":"community.meraki.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4a487c49-5de1-4c8b-85ea-37602ca9283c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"70bdfd14-d8fe-4e98-840c-d0b303985916"}],"recentChangeFlags":null},{"id":"995e57d0-cdb1-46ff-bd64-a89fd92c833f","uri":null,"name":"community-staging.meraki.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5c7ef782-be9a-4934-8b06-eb1efef72aeb","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"995e57d0-cdb1-46ff-bd64-a89fd92c833f"}],"recentChangeFlags":null},{"id":"f901f097-a61a-4447-ad01-f5a58b329620","uri":"","name":"*.cisco.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"00945703-99dc-4806-b347-b719fe0ce377","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"072ba899-5100-4b73-9b45-616ff2ebe8ff","uri":"","name":"meraki.cisco.com/form/contact","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d222e91f-299f-48e8-b4e7-6010bf2ef8a5","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"072ba899-5100-4b73-9b45-616ff2ebe8ff"}],"recentChangeFlags":null},{"id":"47371eab-d1cb-43e6-b215-a5b087a60a85","uri":"","name":"Customer API Keys","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2630d407-340c-4f00-a223-9b34130da366","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"47371eab-d1cb-43e6-b215-a5b087a60a85"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"47371eab-d1cb-43e6-b215-a5b087a60a85"}],"recentChangeFlags":null},{"id":"607e42ab-3c4d-4bc4-8bec-a50efc9caa79","uri":"","name":"Meraki MC Phones","category":"hardware","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"eb54904e-dc71-415b-93e4-e9276f034c56","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"64918b39-a728-4f19-b457-419aa3411279","uri":"","name":"documentation.meraki.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"58be7df3-ea25-43f4-a22d-757577aec704","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"64918b39-a728-4f19-b457-419aa3411279"}],"recentChangeFlags":null},{"id":"9ec8e570-88e5-474f-a2cf-16d33b1b3923","uri":null,"name":"*.workflows.meraki.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3f9d82c3-8707-4379-9ac1-4ef91fd9edf3","sortOrder":10},"sortOrder":10,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9ec8e570-88e5-474f-a2cf-16d33b1b3923"}],"recentChangeFlags":["entirely_new"]}],"inScope":false,"sortOrder":3,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThis program is designed to review and address security issues related to specific Cisco Networking products and applications. Please note that anything that is not explicitly listed as in-scope is considered out-of-scope. Additionally, vulnerabilities specifically related to Adobe Marketo tokens are no longer accepted and will be considered out of scope. If you believe you have found a vulnerability that is outside of this program scope but related to Cisco, please refer to the below resources:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf you need to report a vulnerability in a Cisco product not listed as in-scope for this program, please contact psirt@cisco.com.\u003c/li\u003e\n\u003cli\u003eIf you need to contact Cisco regarding a security incident, please contact incidentresponse@cisco.com.\u003c/li\u003e\n\u003cli\u003eCisco Systems Operational Infrastructure findings can be reported here: https://bugcrowd.com/ciscosecurity\u003c/li\u003e\n\u003cli\u003eFurther information can be found here: https://www.cisco.com/security\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eTemporarily Out of Scope\u003c/em\u003e\u003c/strong\u003e\u003cbr\u003e\nWe are temporarily not accepting submissions related to certain DNS issues, specifically including DNS configuration problems and dangling DNS records or zones.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"b8d0f9a9-52d4-4e2e-8775-12adf4b5c597","code":"cisconetworking","state":"in_progress","endsAt":null,"bountyId":"63a44422-d5f4-4715-889a-4af8783b5cf6","startsAt":"2018-03-05T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Electronics","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/28f4/22c0/c172b7f6/be9870aa1d18d0be2969ab09f912fc21_Cisco_Logo_no_TM_Pantone-White-1200x1200-c3b8a7f.png","logoBackgroundColor":"#07182D","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2018-03-05T19:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/cisconetworking","changelogs":"/engagements/cisconetworking/changelog","submissions":null,"announcements":"/engagements/cisconetworking/announcements","hallOfFame":"/engagements/cisconetworking/hall_of_fames","crowdstream":"/engagements/cisconetworking/crowdstream"},"announcementsCount":15,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/cisconetworking/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=cisconetworking\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/cisconetworking/engagement_subscribers","engagementChangelogsUrl":"/engagements/cisconetworking/changelog","publishedAt":"2026-09-15T21:12:19.217Z","engagementChangelogUrl":"/engagements/cisconetworking/changelog/8b2463ab-810e-4557-ae0c-b91b9c9ec379","createUserFeedbacksUrl":"/engagements/cisconetworking/feedbacks","engagementCrowdstreamUrl":"/engagements/cisconetworking/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}