Cisco Common Services Platform Collector vulnerabilities
19 known vulnerabilities affecting cisco/common_services_platform_collector.
Total CVEs
19
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH1MEDIUM16
Vulnerabilities
Page 1 of 1
CVE-2025-20168MEDIUMCVSS 5.4v2.11v2.11.0.1+3 more2025-01-08
CVE-2025-20168 [MEDIUM] CWE-86 CVE-2025-20168: A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (C
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an a
nvd
CVE-2025-20166MEDIUMCVSS 5.4v2.11v2.11.0.1+3 more2025-01-08
CVE-2025-20166 [MEDIUM] CWE-86 CVE-2025-20166: A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (C
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an a
nvd
CVE-2025-20167MEDIUMCVSS 5.4v2.11v2.11.0.1+3 more2025-01-08
CVE-2025-20167 [MEDIUM] CWE-86 CVE-2025-20167: A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (C
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an a
nvd
CVE-2022-20673MEDIUMCVSS 6.1fixed in 2.10.0.22022-05-27
CVE-2022-20673 [MEDIUM] CWE-79 CVE-2022-20673: Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Col
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based mana
nvd
CVE-2022-20669MEDIUMCVSS 6.1fixed in 2.10.0.22022-05-27
CVE-2022-20669 [MEDIUM] CWE-79 CVE-2022-20669: Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Col
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based mana
nvd
CVE-2022-20668MEDIUMCVSS 6.1fixed in 2.10.0.22022-05-27
CVE-2022-20668 [MEDIUM] CWE-79 CVE-2022-20668: Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Col
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based mana
nvd
CVE-2022-20674MEDIUMCVSS 6.1fixed in 2.10.0.22022-05-27
CVE-2022-20674 [MEDIUM] CWE-79 CVE-2022-20674: Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Col
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based mana
nvd
CVE-2022-20666MEDIUMCVSS 6.1fixed in 2.10.0.22022-05-27
CVE-2022-20666 [MEDIUM] CWE-79 CVE-2022-20666: Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Col
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based mana
nvd
CVE-2022-20671MEDIUMCVSS 6.1fixed in 2.10.0.22022-05-27
CVE-2022-20671 [MEDIUM] CWE-79 CVE-2022-20671: Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Col
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based mana
nvd
CVE-2022-20670MEDIUMCVSS 6.1fixed in 2.10.0.22022-05-27
CVE-2022-20670 [MEDIUM] CWE-79 CVE-2022-20670: Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Col
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based mana
nvd
CVE-2022-20667MEDIUMCVSS 6.1fixed in 2.10.0.22022-05-27
CVE-2022-20667 [MEDIUM] CWE-79 CVE-2022-20667: Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Col
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based mana
nvd
CVE-2022-20672MEDIUMCVSS 6.1fixed in 2.10.0.22022-05-27
CVE-2022-20672 [MEDIUM] CWE-79 CVE-2022-20672: Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Col
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based mana
nvd
CVE-2021-44228CRITICALCVSS 10.0KEVPoCfixed in 2.9.1.3≥ 2.10.0, < 2.10.0.1+7 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2021-40131MEDIUMCVSS 5.4fixed in 2.9.1.12021-11-19
CVE-2021-40131 [MEDIUM] CWE-87 CVE-2021-40131: A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (C
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based management
nvd
CVE-2021-40130MEDIUMCVSS 4.9fixed in 2.9.1.12021-11-19
CVE-2021-40130 [MEDIUM] CWE-284 CVE-2021-40130: A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allo
A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restriction of the syslog configuration. An attacker could exploit this vulnerability by configuring non-log files as s
nvd
CVE-2021-40129MEDIUMCVSS 4.9fixed in 2.9.1.12021-11-19
CVE-2021-40129 [MEDIUM] CWE-89 CVE-2021-40129: A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) co
A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard. This vulnerability is due to insufficient input validation of uploaded files. An attacker could exploit this vulnerability by uploading a file c
nvd
CVE-2021-34774MEDIUMCVSS 4.9≤ 2.102021-11-04
CVE-2021-34774 [MEDIUM] CWE-200 CVE-2021-34774: A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (C
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when responding to a specific API request. An attacker co
nvd
CVE-2021-1538HIGHCVSS 7.2fixed in 2.9.12021-06-04
CVE-2021-1538 [MEDIUM] CWE-78 CVE-2021-1538: A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) co
A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to execute arbitrary code. This vulnerability is due to insufficient sanitization of configuration entries. An attacker could exploit this vulnerability by logging in as a super admin and entering crafted input
nvd
CVE-2019-1723CRITICALCVSS 9.8≥ 2.7.2, < 2.7.4.6≥ 2.8.0, < 2.8.1.22019-03-13
CVE-2019-1723 [CRITICAL] CWE-264 CVE-2019-1723: A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticate
A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account does not have administrator privileges. The vulnerability exists because the affected software has a user account with a default, sta
nvd