VYPR
Medium severity6.1NVD Advisory· Published Jan 26, 2016· Updated May 6, 2026

CVE-2015-6337

CVE-2015-6337

Description

Cisco APIC-EM 1.0.10 is vulnerable to XSS via a crafted hostname in an SNMP response, allowing arbitrary web script injection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco APIC-EM 1.0.10 is vulnerable to XSS via a crafted hostname in an SNMP response, allowing arbitrary web script injection.

Vulnerability

The cross-site scripting vulnerability exists in the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) version 1.0.10. The flaw occurs in the Simple Network Management Protocol (SNMP) query process, where user-supplied input—specifically the hostname returned in an SNMP response—is not properly sanitized before being rendered in the web interface [1].

Exploitation

An unauthenticated, remote attacker can exploit this vulnerability by making a device on the network respond to an SNMP request with a crafted hostname containing malicious web script or HTML. No authentication or special network position beyond the ability to influence an SNMP response is required [1].

Impact

Successful exploitation allows the attacker to inject arbitrary web script or HTML in the context of the affected APIC-EM web interface. This can lead to disclosure of sensitive browser-based information and execution of actions on behalf of an authenticated user who views the malicious content [1].

Mitigation

As of the advisory publication date (January 25, 2016), Cisco had not released a software update to fix this vulnerability. No workarounds are available. Customers are advised to monitor the Cisco Security Advisories and Responses archive for future updates [1].

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • cpe:2.3:a:cisco:application_policy_infrastructure_controller_enterprise_module:1.0.10:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:cisco:application_policy_infrastructure_controller_enterprise_module:1.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:cisco:application_policy_infrastructure_controller_enterprise_module:1.0_ga:*:*:*:*:*:*:*
    • (no CPE)range: =1.0.10

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.