CVE-2025-20167
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-20167 is a vulnerability affecting the web-based management interface of Cisco Common Services Platform Collector (CSPC). An authenticated, remote attacker can exploit this issue through insufficient input validation, leading to cross-site scripting (XSS) attacks. Successful exploitation allows the attacker to execute arbitrary scripts or access sensitive information. The attacker needs a low-privileged account on an affected device to exploit this vulnerability. Currently, there are no software updates or workarounds available from Cisco to address this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.