CVE-2019-1723 describes a critical vulnerability in Cisco Common Services Platform Collector (CSPC) versions 2.7.x and 2.8.x, allowing unauthenticated remote attackers to access the device via a default, static password. This vulnerability is rated 9.8 Critical on the CVSS scale due to its network-based attack vector, low complexity, and high potential for compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation. Cisco has released patches for affected versions (2.7.4.6 and 2.8.1.2).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.7.2, < 2.7.4.6CPE matchmatch criteria | cpe:2.3:a:cisco:common_services_platform_collector:*:*:*:*:*:*:*:* | ||
>= 2.8.0, < 2.8.1.2CPE matchmatch criteria | cpe:2.3:a:cisco:common_services_platform_collector:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.