Work at Cisco Networking? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
The security of our customers is a top priority. We invest heavily in tools, processes and technologies to keep our users and their networks safe. This includes third-party audits, features like two-factor authentication, and our out-of-band cloud management architecture. The Cisco Networking vulnerability rewards program is an important component of our overall security strategy, encouraging external researchers to collaborate with our security team to help keep our customers safe. Be sure to watch for new releases on the Cisco Developer Portal! Ratings/Rewards For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Focus Areas We are specifically looking for high-impact vulnerabilities that affect the security and integrity of our platform and products. While we welcome all valid security reports, we are currently prioritizing the following areas: Insecure Direct Object Reference (IDOR): Vulnerabilities that allow unauthorized access to objects, data, or settings. Privilege Escalation: Flaws that allow a user to gain higher-level permissions (vertical or horizontal escalation). Remote code execution as root Remote root login Remote configuration injections Direct exposure of highly sensitive customer data to unauthorized parties sourced from the Meraki platform, for example, when Cisco or a Cisco employee is responsible for the exposure. This includes: Device secrets Cryptographic keys MV camera footage Customer credentials or PII Full compromise of secure boot "Packet of death" or similar mass Denial of Service
Scope
23 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.ikarem.io | website | ✓ bounty | not set |
| *.meraki.com | website | ✓ bounty | not set |
| *.network-auth.com | website | ✓ bounty | not set |
| Cisco Campus Gateways | hardware | ✓ bounty | not set |
| Cisco Catalyst 9200L Series Switches (Cloud-Managed) | hardware | ✓ bounty | not set |
Show all 23 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| Cisco Meraki Dashboard Mobile Application (iOS and Android) | ios | ✓ bounty | not set |
| Cisco Meraki MG Fixed Wireless Access Devices | hardware | ✓ bounty | not set |
| Cisco Meraki MR Access Points | hardware | ✓ bounty | not set |
| Cisco Meraki MS Switches | hardware | ✓ bounty | not set |
| Cisco Meraki MV Smart Cameras | hardware | ✓ bounty | not set |
| Cisco Meraki MX & Z Series Security Appliances (Including vMX) | hardware | ✓ bounty | not set |
| Cisco Meraki Systems Manager | other | ✓ bounty | not set |
| *.cisco.com | website | out | not set |
| *.workflows.meraki.com | website | out | not set |
| community-staging.meraki.com | website | out | not set |
| community.meraki.com | website | out | not set |
| Customer API Keys | api | out | not set |
| developers.meraki.com | website | out | not set |
| documentation.meraki.com | website | out | not set |
| Meraki MC Phones | hardware | out | not set |
| meraki.cisco.com/form/contact | website | out | not set |
| merakipartners.com | website | out | not set |
| smhelp.meraki.com | website | out | not set |