← Back

CVE-2012-5992

nvd nist
Published: Dec 19, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screens/aaa/mgmtuser_create.html or (2) insert XSS sequences via the headline parameter to screens/base/web_auth_custom.html, aka Bug ID CSCud50283.

Affected (9)

9 products
Wireless Lan Controller Software
2000 Wireless Lan Controller
2100 Wireless Lan Controller
2500 Wireless Lan Controller
4100 Wireless Lan Controller
4400 Wireless Lan Controller
5500 Wireless Lan Controller
7500 Wireless Lan Controller
8500 Wireless Lan Controller
Configuration A
9 vulnerable

Timeline

No history available yet.