Vulnerabilities > Cisco > Common Services Platform Collector

DATE CVE VULNERABILITY TITLE RISK
2021-11-19 CVE-2021-40129 SQL Injection vulnerability in Cisco Common Services Platform Collector
A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard.
network
low complexity
cisco CWE-89
4.9
2021-11-19 CVE-2021-40130 Unspecified vulnerability in Cisco Common Services Platform Collector
A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting.
network
low complexity
cisco
4.9
2021-11-19 CVE-2021-40131 Cross-site Scripting vulnerability in Cisco Common Services Platform Collector
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
5.4
2021-11-04 CVE-2021-34774 Information Exposure vulnerability in Cisco Common Services Platform Collector
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to access sensitive data on an affected system.
network
low complexity
cisco CWE-200
4.9
2021-06-04 CVE-2021-1538 OS Command Injection vulnerability in Cisco Common Services Platform Collector
A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to execute arbitrary code.
network
low complexity
cisco CWE-78
7.2
2019-03-13 CVE-2019-1723 Use of Hard-coded Credentials vulnerability in Cisco Common Services Platform Collector
A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password.
network
low complexity
cisco CWE-798
critical
9.8