10
CVSSv2

CVE-2004-0391

Published: 01/06/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Cisco Wireless LAN Solution Engine (WLSE) 2.0 up to and including 2.5 and Hosting Solution Engine (HSE) 1.7 up to and including 1.7.3 have a hardcoded username and password, which allows remote malicious users to add new users, modify existing users, and change configuration.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco wireless lan solution engine 2.1

cisco wireless lan solution engine 2.2

cisco wireless lan solution engine 2.0

cisco wireless lan solution engine 2.3

cisco wireless lan solution engine 2.4

cisco wireless lan solution engine 2.5

cisco hosting solution engine 1.7.2

cisco hosting solution engine 1.7.3

cisco hosting solution engine 1.7.0

cisco hosting solution engine 1.7.1

cisco hosting solution engine 1.7

Vendor Advisories

A default username/password pair is present in all releases of the Wireless LAN Solution Engine (WLSE) and Hosting Solution Engine (HSE) software A user who logs in using this username has complete control of the device This username cannot be disabled There is no workaround This advisory is available at toolsciscocom/secu ...