Description
Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka Bug ID CSCse93014.
References (7)
Core 7
Core References
Patch vendor-advisory
x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1367
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1017907
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/23460
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24865
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/34132
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33614
Scores
EPSS
0.0166
EPSS Percentile
74.3%
Details
Status
published
Products (2)
cisco/wireless_control_system
4.0
cisco/wireless_control_system
4.0.95
Published
Apr 16, 2007
Tracked Since
Feb 18, 2026