CVE-2006-3288
Unspecified vulnerability in the TFTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51), when configured to use a directory path name that contains a space character, allows remote authenticated users to read and…
Does this matter?
Lower severity and a low EPSS score (2.34%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the TFTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51), when configured to use a directory path name that contains a space character, allows remote authenticated users to read and overwrite arbitrary files via unspecified vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.34% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- cisco/wireless control system
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/20870
- http://securitytracker.com/id?1016398
- http://www.cisco.com/warp/public/707/cisco-sa-20060628-wcs.shtmlPatch
- http://www.osvdb.org/26881
- http://www.securityfocus.com/bid/18701
- http://www.vupen.com/english/advisories/2006/2583
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27440
- http://secunia.com/advisories/20870
- http://securitytracker.com/id?1016398
- http://www.cisco.com/warp/public/707/cisco-sa-20060628-wcs.shtmlPatch
- http://www.osvdb.org/26881
- http://www.securityfocus.com/bid/18701
- http://www.vupen.com/english/advisories/2006/2583
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27440
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.