Cisco Wireless Lan Solution Engine vulnerabilities

4 known vulnerabilities affecting cisco/wireless_lan_solution_engine.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2007-5382CRITICALCVSS 10.0≤ 4.1.91.02007-10-12
CVE-2007-5382 [CRITICAL] CWE-264 CVE-2007-5382: The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and ea The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and earlier to Cisco Wireless Control System (WCS) creates administrator accounts with default usernames and passwords, which allows remote attackers to gain privileges.
nvd
CVE-2006-1961HIGHCVSS 7.5v2.0v2.1+12 more2006-04-21
CVE-2006-1961 [HIGH] CVE-2006-1961: Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell access via shell metacharacters in arguments to
nvd
CVE-2006-1960MEDIUMCVSS 5.8PoCv2.0v2.1+12 more2006-04-21
CVE-2006-1960 [MEDIUM] CVE-2006-1960: Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wir Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.
nvd
CVE-2004-0391CRITICALCVSS 10.0v2.0v2.1+4 more2004-06-01
CVE-2004-0391 [CRITICAL] CVE-2004-0391: Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 thro Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.
nvd