{"api_version":"1","generated_at":"2026-04-23T11:32:32+00:00","cve":"CVE-2007-2032","urls":{"html":"https://cve.report/CVE-2007-2032","api":"https://cve.report/api/cve/CVE-2007-2032.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2032","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2032"},"summary":{"title":"CVE-2007-2032","description":"Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to \"properties of the FTP server,\" aka Bug ID CSCse93014.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-04-16 21:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/24865","name":"http://secunia.com/advisories/24865","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Products Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017907","name":"http://securitytracker.com/id?1017907","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Cisco Wireless Control System Lets Remote Users Read/Write Files and Remote Authenticated Users Gain Elevated Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml","name":"http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Cisco - Networking, Cloud, and Cybersecurity Solutions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/23460","name":"http://www.securityfocus.com/bid/23460","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Wireless Control System Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33614","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33614","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/34132","name":"http://www.osvdb.org/34132","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/1367","name":"http://www.vupen.com/english/advisories/2007/1367","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2032","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2032","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2032","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"wireless_control_system","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2032","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"wireless_control_system","cpe6":"4.0.95","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:23:49.119Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20070412 Multiple Vulnerabilities in the Cisco Wireless Control System","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml"},{"name":"ADV-2007-1367","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1367"},{"name":"1017907","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017907"},{"name":"23460","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/23460"},{"name":"24865","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24865"},{"name":"34132","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/34132"},{"name":"cisco-wcs-ftp-unauthorized-access(33614)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33614"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-04-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to \"properties of the FTP server,\" aka Bug ID CSCse93014."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20070412 Multiple Vulnerabilities in the Cisco Wireless Control System","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml"},{"name":"ADV-2007-1367","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1367"},{"name":"1017907","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017907"},{"name":"23460","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/23460"},{"name":"24865","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24865"},{"name":"34132","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/34132"},{"name":"cisco-wcs-ftp-unauthorized-access(33614)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33614"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-2032","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to \"properties of the FTP server,\" aka Bug ID CSCse93014."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20070412 Multiple Vulnerabilities in the Cisco Wireless Control System","refsource":"CISCO","url":"http://www.cisco.com/warp/public/707/cisco-sa-20070412-wcs.shtml"},{"name":"ADV-2007-1367","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1367"},{"name":"1017907","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017907"},{"name":"23460","refsource":"BID","url":"http://www.securityfocus.com/bid/23460"},{"name":"24865","refsource":"SECUNIA","url":"http://secunia.com/advisories/24865"},{"name":"34132","refsource":"OSVDB","url":"http://www.osvdb.org/34132"},{"name":"cisco-wcs-ftp-unauthorized-access(33614)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33614"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-2032","datePublished":"2007-04-16T21:00:00.000Z","dateReserved":"2007-04-16T00:00:00.000Z","dateUpdated":"2024-08-07T13:23:49.119Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-04-16 21:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:wireless_control_system:4.0:*:*:*:*:*:*:*","matchCriteriaId":"BFF3680D-50CB-4854-84B8-34129DDB2A2A"},{"vulnerable":true,"criteria":"cpe:2.3:h:cisco:wireless_control_system:4.0.95:*:*:*:*:*:*:*","matchCriteriaId":"61A3F299-4388-4940-8046-2E58CF0A7B60"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2032","Ordinal":"1","Title":"CVE-2007-2032","CVE":"CVE-2007-2032","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2032","Ordinal":"1","NoteData":"Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to \"properties of the FTP server,\" aka Bug ID CSCse93014.","Type":"Description","Title":"CVE-2007-2032"},{"CveYear":"2007","CveId":"2032","Ordinal":"2","NoteData":"2007-04-16","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2032","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}