Back

CVE-2019-1723

CRITICAL

A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account does not have administrator privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to the affected system using this account. A successful exploit could allow the attacker to log in to the CSPC using the default account. For Cisco CSPC 2.7.x, Cisco fixed this vulnerability in Release 2.7.4.6. For Cisco CSPC 2.8.x, Cisco fixed this vulnerability in Release 2.8.1.2.

Published: Mar 13, 2019 Modified: Jun 17, 2026
CWE-264 CWE-798

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
cisco common_services_platform_collector * ≥ 2.7.2 < 2.7.4.6
cisco common_services_platform_collector * ≥ 2.8.0 < 2.8.1.2

GitHub Security Advisory GHSA-8gwv-jhp2-f22w

A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.82%

Top 7% most likely to be exploited

Threat Score 40.9 / 100

Data Sources

NVD EPSS GitHub