CVE-2007-2040
published 2007-04-16CVE-2007-2040: Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-coded password, which allows…
PriorityP427medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.36%
28.9th percentile
Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-coded password, which allows attackers with physical access to perform arbitrary actions on the device, aka Bug ID CSCsg15192.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_and_cisco_lightweight_access_points | — | — |
| cisco | wireless_lan_controller_software | >= 3.2 < 3.2.185.0 | 3.2.185.0 |
| cisco | wireless_lan_controller_software | >= 4.0 < 4.0.206.0 | 4.0.206.0 |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4g65-3hrc-pmpq: Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3
ghsa_unreviewed·2022-05-01
CVE-2007-2040 [MEDIUM] GHSA-4g65-3hrc-pmpq: Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3
Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-coded password, which allows attackers with physical access to perform arbitrary actions on the device, aka Bug ID CSCsg15192.
Cisco
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
vendor_cisco·2007-04-12·CVSS 10.0
CVE-2007-2036 [CRITICAL] CWE-264 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
The Cisco Wireless LAN Controller (WLC) manages Cisco Aironet access
points using the Lightweight Access Point Protocol (LWAPP). The WLC contains
multiple vulnerabilities that could result in a denial of service (DoS)
condition, information disclosure, or access control list changes, or allow an
attacker to gain full administrative access.
Cisco has made free software available to address these vulnerabilities
for affected customers. There are workarounds available to mitigate the effects
of these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20070412-wlc.
Cisco
Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
vendor_cisco
CVE-2007-2040 Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
CVE-2007-2040: Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points
The Cisco Wireless LAN Controller (WLC) manages Cisco Aironet access points using the Lightweight Access Point Protocol (LWAPP). The WLC contains multiple vulnerabilities that could result in a denial of service (DoS) condition, information disclosure, or access control list changes, or allow an attacker to gain full administrative access. Cisco has made free software available to address these vulnerabilities for affected customers. There are
CWE: CWE-264, CWE-399, CWE-264, CWE-399
Bug IDs: CSCse02384, CSCsc90179, CSCsg36361, CSCsg15901, CSCsh10841
No detection rules found.
No writeups or analysis indexed.
http://securitytracker.com/id?1017908http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtmlhttp://www.osvdb.org/34133http://www.securityfocus.com/bid/23461http://www.vupen.com/english/advisories/2007/1368https://exchange.xforce.ibmcloud.com/vulnerabilities/33610http://securitytracker.com/id?1017908http://www.cisco.com/warp/public/707/cisco-sa-20070412-wlc.shtmlhttp://www.osvdb.org/34133http://www.securityfocus.com/bid/23461http://www.vupen.com/english/advisories/2007/1368https://exchange.xforce.ibmcloud.com/vulnerabilities/33610
2007-04-16
Published