CVE-2025-20167 Overview
CVE-2025-20167 is a stored cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) and Cisco Crosswork Network Controller. The flaw results from insufficient validation of user-supplied input in specific pages of the interface. An authenticated attacker with at least low-privileged credentials can inject malicious script that executes in the browser context of another user viewing the affected page. Cisco has not released software updates that address this vulnerability, and no vendor workarounds are available.
Critical Impact
A successful exploit allows an attacker to execute arbitrary script code in the context of the management interface or access sensitive browser-based information such as session tokens.
Affected Products
- Cisco Common Services Platform Collector (CSPC) versions 2.11, 2.11.0.1, 2.11.0.2, 2.11.0.3, and 30.1.1-0
- Cisco Crosswork Network Controller (multiple versions per vendor advisory)
- Deployments exposing the web-based management interface to authenticated users
Discovery Timeline
- 2025-01-08 - CVE-2025-20167 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-20167
Vulnerability Analysis
The vulnerability is a cross-site scripting flaw classified under [CWE-86: Improper Neutralization of Invalid Characters in Identifiers in Web Pages]. The web-based management interface accepts user-supplied input and renders it back to interface pages without adequate encoding or sanitization. When another authenticated user loads the affected page, the injected payload executes in that user's browser session.
Exploitation requires authentication and user interaction, and the attack crosses a trust boundary because the injected script runs in the security context of the management application. This can expose session cookies, cross-site request forgery tokens, and other sensitive browser-accessible data belonging to higher-privileged administrators.
Root Cause
The root cause is insufficient input validation and output encoding in the affected pages of the CSPC and Crosswork Network Controller management interface. User-supplied values are stored and later reflected into HTML responses without neutralizing script constructs, enabling script injection.
Attack Vector
The attack vector is network-based and requires an authenticated, low-privileged account on the affected device. The attacker submits a crafted payload through an input field on a vulnerable interface page. When a targeted user, typically an administrator, browses the page containing the stored payload, the script executes with that user's privileges in the management interface. See the Cisco Security Advisory: CSPC XSS and the Cisco Security Advisory: XWORK XSS for the vendor's technical description.
No public proof-of-concept exploit is available, and this vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
Detection Methods for CVE-2025-20167
Indicators of Compromise
- Unexpected <script> tags, javascript: URIs, or HTML event handlers stored in CSPC or Crosswork Network Controller configuration fields
- Administrator session activity originating from unusual IP addresses shortly after visiting an affected interface page
- Outbound HTTP requests from administrator browsers to attacker-controlled domains referencing the management interface as the origin
Detection Strategies
- Review web server and application audit logs for POST requests from low-privileged accounts containing HTML or script metacharacters targeting the CSPC or Crosswork management interface
- Inspect stored configuration data and user-supplied fields in the interface for embedded markup that should not appear in normal input
- Correlate authenticated sessions with anomalous browser behavior such as unexpected API calls to privileged endpoints
Monitoring Recommendations
- Enable and centralize access logging for the CSPC and Crosswork Network Controller web interfaces
- Alert on authentication events for low-privileged accounts followed by administrative actions in short time windows
- Monitor for changes to management interface content and configuration objects outside approved change windows
How to Mitigate CVE-2025-20167
Immediate Actions Required
- Restrict access to the CSPC and Crosswork Network Controller management interfaces to trusted administrative networks and jump hosts only
- Audit all accounts with access to the web interface and remove or disable any unnecessary low-privileged accounts
- Enforce unique, high-entropy credentials and multi-factor authentication for all users of the management interface
- Instruct administrators to avoid browsing arbitrary pages of the interface from browsers used for other sensitive activity
Patch Information
At the time of publication, Cisco has not released software updates that address CVE-2025-20167. Monitor the Cisco Security Advisory: CSPC XSS and the Cisco Security Advisory: XWORK XSS for updated fixed-release information.
Workarounds
- Cisco has stated that no workarounds address this vulnerability
- As compensating controls, place the management interface behind a VPN or bastion host and enforce strict network access control lists
- Deploy a reverse proxy or web application firewall in front of the interface to filter script payloads in request parameters where feasible
- Use dedicated administrative browsers or profiles to reduce the impact of session token theft
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.