CVE-2004-0391

Cisco Wireless LAN Solution Engine 2.0-2.5 and Hosting Solution Engine 1.7-1.7.3 - Hardcoded Credentials

Title source: llm
STIX 2.1

Description

Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.

References (5)

Core 5
Core References
Patch, Vendor Advisory third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/o-111.shtml
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20040407-username.shtml
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/659228
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10076
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15773

Scores

EPSS 0.0458
EPSS Percentile 90.6%

Details

Status published
Products (11)
cisco/hosting_solution_engine 1.7
cisco/hosting_solution_engine 1.7.0
cisco/hosting_solution_engine 1.7.1
cisco/hosting_solution_engine 1.7.2
cisco/hosting_solution_engine 1.7.3
cisco/wireless_lan_solution_engine 2.0
cisco/wireless_lan_solution_engine 2.1
cisco/wireless_lan_solution_engine 2.2
cisco/wireless_lan_solution_engine 2.3
cisco/wireless_lan_solution_engine 2.4
... and 1 more
Published Jun 01, 2004
Tracked Since Feb 18, 2026