6.8
CVE-2012-5992
- EPSS 0.59%
- Veröffentlicht 19.12.2012 11:56:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via screens/aaa/mgmtuser_create.html or (2) insert XSS sequences via the headline parameter to screens/base/web_auth_custom.html, aka Bug ID CSCud50283.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Wireless Lan Controller Software Version7.2.110.0
Cisco ≫ 2500 Wireless Lan Controller Version-
Cisco ≫ 5500 Wireless Lan Controller Version-
Cisco ≫ 7500 Wireless Lan Controller Version-
Cisco ≫ 8500 Wireless Lan Controller Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.59% | 0.683 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.