First published: Fri Oct 12 2007(Updated: )
The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and earlier to Cisco Wireless Control System (WCS) creates administrator accounts with default usernames and passwords, which allows remote attackers to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Wireless LAN Solution Engine | <=4.1.91.0 | |
Cisco Wireless Control System software | =4.1.91.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5382 is considered a high severity vulnerability due to the potential for unauthorized access through default credentials.
To fix CVE-2007-5382, change all default usernames and passwords in the Cisco Wireless Control System and Wireless LAN Solution Engine settings.
CVE-2007-5382 affects Cisco Wireless LAN Solution Engine versions up to and including 4.1.91.0 and Cisco Wireless Control System version 4.1.91.0.
CVE-2007-5382 impacts systems that utilize CiscoWorks Wireless LAN Solution Engine and Cisco Wireless Control System.
Yes, CVE-2007-5382 can be exploited remotely, allowing attackers to gain elevated privileges.