CVE-2015-6337
Description
Cisco APIC-EM 1.0.10 is vulnerable to XSS via a crafted hostname in an SNMP response, allowing arbitrary web script injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cisco APIC-EM 1.0.10 is vulnerable to XSS via a crafted hostname in an SNMP response, allowing arbitrary web script injection.
Vulnerability
The cross-site scripting vulnerability exists in the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) version 1.0.10. The flaw occurs in the Simple Network Management Protocol (SNMP) query process, where user-supplied input—specifically the hostname returned in an SNMP response—is not properly sanitized before being rendered in the web interface [1].
Exploitation
An unauthenticated, remote attacker can exploit this vulnerability by making a device on the network respond to an SNMP request with a crafted hostname containing malicious web script or HTML. No authentication or special network position beyond the ability to influence an SNMP response is required [1].
Impact
Successful exploitation allows the attacker to inject arbitrary web script or HTML in the context of the affected APIC-EM web interface. This can lead to disclosure of sensitive browser-based information and execution of actions on behalf of an authenticated user who views the malicious content [1].
Mitigation
As of the advisory publication date (January 25, 2016), Cisco had not released a software update to fix this vulnerability. No workarounds are available. Customers are advised to monitor the Cisco Security Advisories and Responses archive for future updates [1].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3cpe:2.3:a:cisco:application_policy_infrastructure_controller_enterprise_module:1.0.10:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:cisco:application_policy_infrastructure_controller_enterprise_module:1.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:application_policy_infrastructure_controller_enterprise_module:1.0_ga:*:*:*:*:*:*:*
- (no CPE)range: =1.0.10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.