VulnerabilityModified
CVE-2006-5288
Cisco 2700 Series Wireless Location Appliances before 2.1.34.0 have a default administrator username "root" and password "password," which allows remote attackers to obtain administrative privileges, aka Bug ID CSCsb92893.
HIGH 10.0EPSS 3.59%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco 2700 Series Wireless Location Appliances before 2.1.34.0 have a default administrator username "root" and password "password," which allows remote attackers to obtain administrative privileges, aka Bug ID CSCsb92893.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.59% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- cisco/2700 wireless location appliance
- Source
- cve@mitre.org
References
- http://securitytracker.com/id?1017056
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080758bae.shtmlPatch
- http://www.osvdb.org/30913
- http://www.securityfocus.com/bid/20490
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29497
- http://securitytracker.com/id?1017056
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080758bae.shtmlPatch
- http://www.osvdb.org/30913
- http://www.securityfocus.com/bid/20490
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29497
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.