CVE-2012-5991
published 2012-12-19CVE-2012-5991: screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a denial of…
PriorityP334medium6.3CVSS 2.0
AVNACMAuSCNINAC
EXPLOIT
EPSS
5.52%
91.9th percentile
screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a denial of service (device reload) via a certain buttonClicked value in an internal webauth_type request, aka Bug ID CSCud50209.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_software | — | — |
CVSS provenance
nvdv2.06.3MEDIUMAV:N/AC:M/Au:S/C:N/I:N/A:C
vendor_cisco6.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6hqg-ghvh-32h4: screens/base/web_auth_custom
ghsa_unreviewed·2022-05-17
CVE-2012-5991 [MEDIUM] GHSA-6hqg-ghvh-32h4: screens/base/web_auth_custom
screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a denial of service (device reload) via a certain buttonClicked value in an internal webauth_type request, aka Bug ID CSCud50209.
Cisco
Cisco Wireless LAN Controller Software Form Post Denial of Service Vulnerability
vendor_cisco·2012-12-13·CVSS 6.3
CVE-2012-5991 [MEDIUM] CWE-20 Cisco Wireless LAN Controller Software Form Post Denial of Service Vulnerability
Cisco Wireless LAN Controller Software Form Post Denial of Service Vulnerability
Cisco Wireless LAN Controller Software contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to insufficient validation of user-supplied input to the affected software. An authenticated, remote attacker could exploit the vulnerability by sending crafted HTTP GET requests to the targeted system. When processed, the malicious requests could cause the vulnerable software terminate abnormally, denying service to legitimate users.
Functional code that exploits the vulnerability is publicly available.
Cisco confirmed the vulnerability in a security bug report; however, software updates are not available.
Only users who
No detection rules found.
No writeups or analysis indexed.
2012-12-19
Published