{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:00:17Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20070412-CVE-2007-2034","slug":"cisco-sa-20070412-cve-2007-2034","vendor":"Cisco","title":"Cisco Wireless Control System Privilege Escalation Vulnerability","summary":"Cisco Wireless Control System (WCS) versions prior to 4.0.87.0 contains a vulnerability that could allow an authenticated, remote attacker to gain escalated privileges on the affected system. This vulnerability exists due to insufficient access controls on the Cisco&nbsp;WCS configuration page used to assign group membership.&nbsp; An authenticated, remote attacker could exploit this vulnerability by accessing this page and adding their account to the SuperUsers group.&nbsp; This grants the&nbsp;attacker full privileges&nbsp;in the WCS application, allowing the attacker to control all devices managed by the WCS. Cisco has confirmed this vulnerability and released software updates. To exploit this vulnerability, an attacker must authenticate to the WCS.&nbsp; No additional credentials are required.&nbsp; As a result of the vulnerability described in Alert&nbsp;13036,&nbsp;any authenticated user level access to the WCS is sufficient to access some WCS configuration pages without the need for further&nbsp;authentication.&nbsp; This vulnerability relates specifically to the ability to access a WCS configuration page that can be used to add an application user to an application group.&nbsp; Because&nbsp;of this vulnerability, it is possible for any WCS user to add their user account to the SuperUsers group.&nbsp; The attacker must also know the correct URL to enter to reach the vulnerable page, however.&nbsp; This reduces the likelihood of an attack somewhat, although an attacker who is familiar with the WCS product would have little trouble locating the correct page.","severity":"Medium","published_at":"2007-04-12T16:56:49Z","updated_at":"2007-04-12T16:56:49Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20070412-CVE-2007-2034","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20070412-CVE-2007-2034/csaf/Cisco-SA-20070412-CVE-2007-2034.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.02098},"cves":[{"id":"CVE-2007-2034","kev":false,"epss":{"score":0.02098,"percentile":0.79642,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"}}],"public_evidence":[{"product":{"name":"Cisco Wireless Control System (WCS) Software","slug":"cisco-wireless-control-system-wcs-software","vendor":"Cisco"},"cve":{"id":"CVE-2007-2034"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:26:22Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Wireless Control System (WCS) Software","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.02098,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"},"published_at":"2007-04-12T16:56:49Z","updated_at":"2007-04-12T16:56:49Z","advisory_updated_at":"2007-04-12T16:56:49Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20070412-CVE-2007-2034","row_display_order":1}]}