Lucene search

K
cvelistCiscoCVELIST:CVE-2021-1538
HistoryJun 04, 2021 - 4:45 p.m.

CVE-2021-1538 Cisco Common Services Platform Collector Command Injection Vulnerability

2021-06-0416:45:54
CWE-78
cisco
www.cve.org
4
cisco common services platform collector
vulnerability
remote code execution
input sanitization

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

EPSS

0.002

Percentile

54.5%

A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to execute arbitrary code. This vulnerability is due to insufficient sanitization of configuration entries. An attacker could exploit this vulnerability by logging in as a super admin and entering crafted input to configuration options on the CSPC configuration dashboard. A successful exploit could allow the attacker to execute remote code as root.

CNA Affected

[
  {
    "product": "Cisco Common Services Platform Collector Software",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

EPSS

0.002

Percentile

54.5%

Related for CVELIST:CVE-2021-1538