Cisco-SA-20121213-CVE-2012-5992
Cisco Wireless LAN Controller Cross-Site Request Forgery Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
Cisco Wireless LAN Controller (WLC) Software contains a vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site request forgery attacks on a targeted system. The vulnerability is due to insufficient sanitization of user-supplied input processed by the WLC management web interface of the affected software. An unauthenticated, remote attacker could exploit this vulnerability by convincing a targeted user to follow a malicious link. Successful exploitation could allow the attacker to gain unauthorized access to the affected application, which could be used to conduct further attacks. Cisco confirmed the vulnerability in a security bug report; however, software updates are not available. To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link. Cisco would like to thank security researcher Jacob Holcomb for reporting this vulnerability.
| Product | CVE |
|---|---|
| Cisco Wireless LAN Controller (WLC) | CVE-2012-5992 |