CVE-2010-0594
Description
Cross-site scripting (XSS) vulnerability in Cisco Router and Security Device Manager (SDM) allows remote attackers to inject arbitrary web script or HTML via unknown vectors, aka Bug ID CSCtb38467.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cisco Router and Security Device Manager (SDM) contains a cross-site scripting vulnerability that allows remote attackers to inject arbitrary script via unknown vectors.
Vulnerability
Cisco Router and Security Device Manager (SDM), a web-based device management tool for Cisco routers, contains a cross-site scripting (XSS) vulnerability. The vulnerability exists in an unspecified component of SDM and can be triggered by unknown vectors. Cisco Bug ID CSCtb38467 tracks this issue. Affected versions include Cisco Router and Security Device Manager (SDM) as described in vendor advisories [1][2].
Exploitation
An attacker can exploit this vulnerability remotely without authentication by crafting a malicious request that injects arbitrary web script or HTML into the SDM interface [1]. The attack requires user interaction, as the victim must browse to the SDM administration page and view the injected content [2].
Impact
Successful exploitation allows an attacker to execute arbitrary script in the user's web browser within the context of the SDM application [1][2]. This can lead to unauthorized actions, such as accessing session tokens or manipulating settings, potentially resulting in partial integrity compromise. Confidentiality and availability are not directly affected according to CVSS v2 scoring [1].
Mitigation
Cisco recommends updating SDM to the latest version according to vendor-provided information [1][2]. No specific fixed version number is disclosed in the available references. The vendor has not published further workaround details, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3cpe:2.3:a:cisco:router_and_security_device_manager:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cisco:router_and_security_device_manager:*:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:router_and_security_device_manager:2.5:*:*:*:*:*:*:*
- (no CPE)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.