Lucene search

K
cvelistCiscoCVELIST:CVE-2021-40131
HistoryNov 18, 2021 - 11:50 p.m.

CVE-2021-40131 Cisco Common Services Platform Collector Stored Cross-Site Scripting Vulnerability

2021-11-1823:50:29
CWE-87
cisco
www.cve.org
1
cisco common services platform collector
cross-site scripting
vulnerability
web-based management interface
authenticated
remote attacker
configuration
malicious code
arbitrary code
sensitive information

CVSS3

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

28.6%

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based management interface. An attacker could exploit this vulnerability by adding malicious code to the configuration by using the web-based management interface. A successful exploit could allow the attacker to execute arbitrary code in the context of the interface or access sensitive, browser-based information.

CNA Affected

[
  {
    "product": "Cisco Common Services Platform Collector Software",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS3

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

28.6%

Related for CVELIST:CVE-2021-40131