First published: Fri Oct 13 2006(Updated: )
Cisco 2700 Series Wireless Location Appliances before 2.1.34.0 have a default administrator username "root" and password "password," which allows remote attackers to obtain administrative privileges, aka Bug ID CSCsb92893.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco 2700 Wireless Location Appliance | =1.1.73.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5288 is classified as a high severity vulnerability due to the use of default and easily guessable credentials.
To fix CVE-2006-5288, change the default administrator username and password from 'root' and 'password' to strong, unique credentials.
CVE-2006-5288 affects Cisco 2700 Series Wireless Location Appliances before version 2.1.34.0.
Yes, CVE-2006-5288 can be exploited remotely since it allows attackers to log in using the default administrator credentials.
Yes, upgrading the affected devices to version 2.1.34.0 or later will mitigate the vulnerability.