CVE-2025-20166
MEDIUMDescription
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device. Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | crosswork_network_controller |
| cisco | crosswork_network_controller |
| cisco | crosswork_network_controller |
| cisco | common_services_platform_collector |
| cisco | common_services_platform_collector |
| cisco | common_services_platform_collector |
| cisco | common_services_platform_collector |
| cisco | common_services_platform_collector |
References
Frequently Asked Questions
What is CVE-2025-20166? +
How severe is CVE-2025-20166? +
What products are affected by CVE-2025-20166? +
How do I check if I'm vulnerable to CVE-2025-20166? +
Related Vulnerabilities
Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to …
Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to …
A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability …
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker …
A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker …
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after …