PT-2021-7442 · Cisco · Cisco Common Services Platform Collector

Aaron Rhodes

+1

·

Published

2021-06-02

·

Updated

2021-06-14

·

CVE-2021-1538

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Common Services Platform Collector (CSPC) (affected versions not specified)
Description A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to execute arbitrary code. This issue is due to insufficient sanitization of configuration entries. An attacker could exploit this vulnerability by logging in as a super admin and entering crafted input to configuration options on the CSPC configuration dashboard. A successful exploit could allow the attacker to execute remote code as root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06335
CVE-2021-1538

Affected Products

Cisco Common Services Platform Collector