CVE-2007-2032
Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka Bug ID CSCse93014.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- cisco/wireless control system
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24865Vendor Advisory
- http://securitytracker.com/id?1017907
- http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtmlPatch
- http://www.osvdb.org/34132
- http://www.securityfocus.com/bid/23460
- http://www.vupen.com/english/advisories/2007/1367
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33614
- http://secunia.com/advisories/24865Vendor Advisory
- http://securitytracker.com/id?1017907
- http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtmlPatch
- http://www.osvdb.org/34132
- http://www.securityfocus.com/bid/23460
- http://www.vupen.com/english/advisories/2007/1367
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33614
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.