CVE-2021-40129
Cisco Common Services Platform Collector SQL Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to submit a SQL query through the CSPC configuration dashboard. This vulnerability is due to insufficient input validation of uploaded files. An attacker could exploit this vulnerability by uploading a file containing a SQL query to the configuration dashboard. A successful exploit could allow the attacker to read restricted information from the CSPC SQL database.
Una vulnerabilidad en el panel de configuración de Cisco Common Services Platform Collector (CSPC) podría permitir a un atacante remoto autenticado enviar una consulta SQL mediante el panel de configuración de CSPC. Esta vulnerabilidad es debido a una comprobación insuficiente de entrada de los archivos cargados. Un atacante podría aprovechar esta vulnerabilidad al cargar un archivo que contenga una consulta SQL en el panel de configuración. Una explotación con éxito podría permitir al atacante leer información restringida de la base de datos SQL de CSPC
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-08-25 CVE Reserved
- 2021-11-18 CVE Published
- 2024-02-09 EPSS Updated
- 2024-11-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CSPC-SQLI-unVPTn5 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Common Services Platform Collector Search vendor "Cisco" for product "Common Services Platform Collector" | < 2.9.1.1 Search vendor "Cisco" for product "Common Services Platform Collector" and version " < 2.9.1.1" | - |
Affected
|