First published: Mon Apr 16 2007(Updated: )
Cisco Wireless Control System (WCS) before 4.0.66.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain network organization data via a direct request for files in certain directories, aka Bug ID CSCsg04301.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Wireless Control System software | <=4.0.95 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2035 is considered to have a medium severity due to improper access control allowing unauthorized data access.
To fix CVE-2007-2035, upgrade your Cisco Wireless Control System to version 4.0.66.0 or later.
CVE-2007-2035 exposes sensitive network organization data stored under the web root.
Yes, CVE-2007-2035 can be exploited remotely by attackers who can make direct requests to specific files.
CVE-2007-2035 affects Cisco Wireless Control System versions prior to 4.0.66.0.