Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka Bug ID CSCse93014.
Link | Tags |
---|---|
http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml | patch vendor advisory |
http://www.vupen.com/english/advisories/2007/1367 | vdb entry |
http://securitytracker.com/id?1017907 | vdb entry |
http://www.securityfocus.com/bid/23460 | vdb entry |
http://secunia.com/advisories/24865 | third party advisory vendor advisory |
http://www.osvdb.org/34132 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33614 | vdb entry |