Lucene search

K

Common Services Platform Collector Security Vulnerabilities

cve
cve

CVE-2019-1723

A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account does not have administrator privileges. The vulnerability exists because the affe...

9.8CVSS

9.3AI Score

0.003EPSS

2019-03-13 09:29 PM
41
cve
cve

CVE-2021-1538

A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to execute arbitrary code. This vulnerability is due to insufficient sanitization of configuration entries. An attacker could exploit this vulnerability by...

7.2CVSS

7.3AI Score

0.002EPSS

2021-06-04 05:15 PM
39
5
cve
cve

CVE-2021-34774

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when ...

4.9CVSS

4.8AI Score

0.001EPSS

2021-11-04 04:15 PM
49
cve
cve

CVE-2021-40129

A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard. This vulnerability is due to insufficient input validation of uploaded files. An attacker c...

4.9CVSS

5.1AI Score

0.001EPSS

2021-11-19 12:15 AM
27
cve
cve

CVE-2021-40130

A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restriction of the syslog configuration. An attacker could exploit ...

4.9CVSS

5AI Score

0.001EPSS

2021-11-19 12:15 AM
30
cve
cve

CVE-2021-40131

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplie...

5.5CVSS

5.3AI Score

0.001EPSS

2021-11-19 12:15 AM
42
cve
cve

CVE-2021-44228

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message ...

10CVSS

9.8AI Score

0.965EPSS

2021-12-10 10:15 AM
3798
In Wild
399
cve
cve

CVE-2022-20666

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
81
4
cve
cve

CVE-2022-20667

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
156
4
cve
cve

CVE-2022-20668

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
62
4
cve
cve

CVE-2022-20669

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
81
4
cve
cve

CVE-2022-20670

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
46
2
cve
cve

CVE-2022-20671

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
68
2
cve
cve

CVE-2022-20672

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
61
3
cve
cve

CVE-2022-20673

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
77
2
cve
cve

CVE-2022-20674

Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient va...

6.1CVSS

5.9AI Score

0.001EPSS

2022-05-27 02:15 PM
60
2