Severity
7.5HIGH
EPSS
1.0%
top 22.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 28
Latest updateMay 1

Description

The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) uses an undocumented, hard-coded username and password, which allows remote authenticated users to read, and possibly modify, sensitive configuration data (aka bugs CSCsd15955).

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x669-5vqg-q3cw: The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 32022-05-01
CVEList
CVE-2006-3285: The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 32006-06-28

📋Vendor Advisories

1
Cisco
Multiple Vulnerabilities in Wireless Control System2006-06-28