CVE-2006-3285
 
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) uses an undocumented, hard-coded username and password, which allows remote authenticated users to read, and possibly modify, sensitive configuration data (aka bugs CSCsd15955).
La base de datos interna en Cisco Wireless Control System (WCS) para Linux y Windows anterior a v3.2(51) utiliza un nombre de usuario indocumentados no modificable y una contraseƱa, lo cual permite a usuarios remotos autenticados leer, y posiblemente modificar, datos de configuraciĆ³n confidenciales (alias errores CSCsd15955).
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-06-28 CVE Reserved
- 2006-06-28 CVE Published
- 2023-08-24 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/20870 | Third Party Advisory | |
http://securitytracker.com/id?1016398 | Vdb Entry | |
http://www.osvdb.org/26884 | Vdb Entry | |
http://www.securityfocus.com/bid/18701 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/2583 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27438 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.cisco.com/warp/public/707/cisco-sa-20060628-wcs.shtml | 2017-07-20 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Wireless Control System Search vendor "Cisco" for product "Wireless Control System" | <= 3.2\(40\) Search vendor "Cisco" for product "Wireless Control System" and version " <= 3.2\(40\)" | - |
Affected
|