{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T16:34:37Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20121213-CVE-2012-5991","slug":"cisco-sa-20121213-cve-2012-5991","vendor":"Cisco","title":"Cisco Wireless LAN Controller Software Form Post Denial of Service Vulnerability","summary":"Cisco Wireless LAN Controller Software contains a vulnerability that could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of user-supplied input to the affected software. An authenticated, remote attacker could exploit the vulnerability by sending crafted HTTP GET requests to the targeted system. When processed, the malicious requests could cause the vulnerable software terminate abnormally, denying service to legitimate users. Functional code that exploits the vulnerability is publicly available. Cisco confirmed the vulnerability in a security bug report; however, software updates are not available. Only users who can authenticate to the affected software could exploit the vulnerability. Affected systems typically have restricted access, limiting the potential for exploitation. A related vulnerability in the affected software could allow an unauthenticated, remote attacker to exploit the vulnerability. However, the exploit relies upon user interaction, and the targeted user must have authenticated access to the affected system.","severity":"Medium","published_at":"2012-12-13T22:20:26Z","updated_at":"2012-12-13T22:20:26Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20121213-CVE-2012-5991","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20121213-CVE-2012-5991/csaf/Cisco-SA-20121213-CVE-2012-5991.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.05519},"cves":[{"id":"CVE-2012-5991","kev":false,"epss":{"score":0.05519,"percentile":0.91934,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"}}],"public_evidence":[{"product":{"name":"Cisco Wireless LAN Controller (WLC)","slug":"cisco-wireless-lan-controller-wlc","vendor":"Cisco"},"cve":{"id":"CVE-2012-5991"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:34:01Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"7.0.116.0; 7.0.220.0; 7.0.98.0; 7.0.98.218; 7.1.91.0; 7.2.103.0","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.05519,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"},"published_at":"2012-12-13T22:20:26Z","updated_at":"2012-12-13T22:20:26Z","advisory_updated_at":"2012-12-13T22:20:26Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20121213-CVE-2012-5991","row_display_order":1}]}