MEDIUM · 6.8

CVE-2012-5992

Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators ...

Vulnerability Description

Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screens/aaa/mgmtuser_create.html or (2) insert XSS sequences via the headline parameter to screens/base/web_auth_custom.html, aka Bug ID CSCud50283.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CiscoWireless Lan Controller Software7.2.110.0
Cisco2000 Wireless Lan ControllerAll versions
Cisco2100 Wireless Lan ControllerAll versions
Cisco2500 Wireless Lan Controller-
Cisco4100 Wireless Lan ControllerAll versions
Cisco4400 Wireless Lan ControllerAll versions
Cisco5500 Wireless Lan Controller-
Cisco7500 Wireless Lan Controller-
Cisco8500 Wireless Lan Controller-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-5992?

CVE-2012-5992 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators ...

How severe is CVE-2012-5992?

CVE-2012-5992 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-5992?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Wireless Lan Controller Software, Cisco 2000 Wireless Lan Controller, Cisco 2100 Wireless Lan Controller, Cisco 2500 Wireless Lan Controller, Cisco 4100 Wireless Lan Controller.