CVE-2007-2035

Severity
7.8HIGH
EPSS
0.5%
top 32.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateMay 1

Description

Cisco Wireless Control System (WCS) before 4.0.66.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain network organization data via a direct request for files in certain directories, aka Bug ID CSCsg04301.

CVSS vector

AV:N/AC:L/C:C/I:N/A:NExploitability: 10.0 | Impact: 6.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-fmrr-39jx-v9r4: Cisco Wireless Control System (WCS) before 42022-05-01
CVEList
CVE-2007-2035: Cisco Wireless Control System (WCS) before 42007-04-16

📋Vendor Advisories

1
Cisco
Multiple Vulnerabilities in the Cisco Wireless Control System2007-04-12