First published: Wed Jun 28 2006(Updated: )
HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames and directory paths via a direct URL request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Wireless Control System software | <=3.2\(51\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3290 is categorized as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2006-3290, upgrade your Cisco Wireless Control System software to a version above 3.2(51).
CVE-2006-3290 affects Cisco Wireless Control System for both Linux and Windows prior to version 3.2(51).
CVE-2006-3290 allows remote attackers to access sensitive information, including usernames and directory paths.
While there may not be public exploits available, CVE-2006-3290 presents a significant risk of unauthorized access if left unpatched.