CVE-2025-20166 Details
Description
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device. Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Common Services Platform Collector (CSPC). This vulnerability allows an authenticated, remote attacker to conduct XSS attacks against users of the interface. The issue arises from insufficient validation of user-supplied input, enabling attackers to inject malicious code into specific pages of the interface. Exploitation of this vulnerability could result in the execution of arbitrary script code in the context of the affected interface or access to sensitive, browser-based information. To exploit this vulnerability, an attacker must have at least a low-privileged account on an affected device.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-86 | Improper Neutralization of Invalid Characters in Identifiers in Web Pages | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco crosswork network controller | >= 5.0.0, < 5.0.4 >= 6.0.0, < 6.0.3 >= 7.0.0, < 7.0.1 |
CPE
Remediation
| |
| cisco common services platform collector | 2.11 2.11.0.1 2.11.0.2 2.11.0.3 30.1.1-0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 23, 2025 | Initial Analysis | [email protected] |
| Jan 8, 2025 | New CVE Received | [email protected] |