PT-2021-5677 · Cisco · Cisco Common Services Platform Collector
Aaron Rhodes
+1
·
Published
2021-11-17
·
Updated
2021-11-23
·
CVE-2021-40129
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Common Services Platform Collector (affected versions not specified)
Description
The issue is related to insufficient input validation of uploaded files in the configuration dashboard of Cisco Common Services Platform Collector. This could allow an authenticated, remote attacker to submit a SQL query through the configuration dashboard by uploading a file containing a SQL query. A successful exploit could allow the attacker to read restricted information from the CSPC SQL database.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Common Services Platform Collector