CVE-2026-88263
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| XikeStor | SKS8310-8X | 0 < V1.04.B09 | affected |
| XikeStor | SKS8300-8T | 0 < V1.04.B09 | affected |
| XikeStor | SKS8300-12E2T2X | 0 < V1.04.B09 | affected |
Weaknesses
- CWE-306: Missing authentication for critical function
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.