[原文]HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames and directory paths via a direct URL request.
Cisco Wireless Control System (WCS) HTTP Server Permission Weakness Information Disclosure
Remote / Network Access,
Loss of Confidentiality
Wireless Control System contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by inadequate access controls on unspecified directories, which may disclose username and/or directory path information resulting in a loss of confidentiality.
Upgrade to version 3.2(63) or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.