CVE-2004-0391

4 documents4 sources
Severity
10.0CRITICAL
EPSS
0.8%
top 25.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1
Latest updateApr 29

Description

Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5j5j-qcr8-cxv4: Cisco Wireless LAN Solution Engine (WLSE) 22022-04-29
CVEList
CVE-2004-0391: Cisco Wireless LAN Solution Engine (WLSE) 22004-04-16

📋Vendor Advisories

1
Cisco
A Default Username and Password in WLSE and HSE Devices2004-04-07