[原文]The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(63) stores a hard-coded username and password in plaintext within unspecified files, which allows remote authenticated users to access the database (aka bug CSCsd15951).
Cisco Wireless Control System (WCS) Internal Database Cleartext Account Disclosure
Remote / Network Access,
Loss of Confidentiality
Wireless Control System contains a flaw that may lead to an unauthorized information disclosure. Several WCS files contain the undocumented database username and password (OSVDB 26882) stored in cleartext, resulting in a loss of confidentiality.
Upgrade to version 3.2(63) or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.