- Description
- Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka Bug ID CSCse93014.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:wireless_control_system:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFF3680D-50CB-4854-84B8-34129DDB2A2A"
},
{
"criteria": "cpe:2.3:h:cisco:wireless_control_system:4.0.95:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61A3F299-4388-4940-8046-2E58CF0A7B60"
}
],
"operator": "OR"
}
]
}
]