CVE-2007-2036
published 2007-04-16CVE-2007-2036: The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-write…
PriorityP338critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.57%
83.5th percentile
The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-write community private, which allows remote attackers to read and modify SNMP variables, aka Bug ID CSCse02384.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_and_cisco_lightweight_access_points | — | — |
| cisco | wireless_lan_controller_software | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
vendor_cisco·2007-04-12·CVSS 10.0
CVE-2007-2036 [CRITICAL] CWE-264 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
The Cisco Wireless LAN Controller (WLC) manages Cisco Aironet access
points using the Lightweight Access Point Protocol (LWAPP). The WLC contains
multiple vulnerabilities that could result in a denial of service (DoS)
condition, information disclosure, or access control list changes, or allow an
attacker to gain full administrative access.
Cisco has made free software available to address these vulnerabilities
for affected customers. There are workarounds available to mitigate the effects
of these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070412-wlc.
Cisco
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
vendor_cisco
CVE-2007-2036 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
CVE-2007-2036: Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
The Cisco Wireless LAN Controller (WLC) manages Cisco Aironet access points using the Lightweight Access Point Protocol (LWAPP). The WLC contains multiple vulnerabilities that could result in a denial of service (DoS) condition, information disclosure, or access control list changes, or allow an attacker to gain full administrative access. Cisco has made free software available to address these vulnerabilities for affected customers. There are
CWE: CWE-264, CWE-399, CWE-264, CWE-399
Bug IDs: CSCse02384, CSCsc90179, CSCsg36361, CSCsg15901, CSCsh10841
GHSA
GHSA-vv79-p5p7-73ch: The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-w
ghsa_unreviewed·2022-05-01
CVE-2007-2036 [HIGH] GHSA-vv79-p5p7-73ch: The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-w
The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 20070419 uses the default read-only community public, and the default read-write community private, which allows remote attackers to read and modify SNMP variables, aka Bug ID CSCse02384.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://securitytracker.com/id?1017908http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtmlhttp://www.osvdb.org/34134http://www.securityfocus.com/bid/23461http://www.vupen.com/english/advisories/2007/1368https://exchange.xforce.ibmcloud.com/vulnerabilities/33604http://securitytracker.com/id?1017908http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtmlhttp://www.osvdb.org/34134http://www.securityfocus.com/bid/23461http://www.vupen.com/english/advisories/2007/1368https://exchange.xforce.ibmcloud.com/vulnerabilities/33604
2007-04-16
Published