[Japanese]

JVNDB-2026-000134

XikeStor Layer3 switches miss authentication for downloading configuration data

Overview

XikeStor Layer3 switches contain the vulnerability listed below.
  • Missing authentication for downloading configuration (CWE-306) - CVE-2026-88263
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 7.5 (High) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: None
  • Availability Impact: None
CVSS v4 Severity
Base Metrics: 8.7 (High) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): None
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
Affected Products


XikeStor
  • SKS8300-12E2T2X versions prior to V1.04.B09
  • SKS8300-8T versions prior to V1.04.B09
  • SKS8310-8X versions prior to V1.04.B09

Impact

Confidential information, such as network configurations or passwords, may be retrieved by an unauthenticated attacker.
This allows the attacker to operate the affected product improperly or to exploit the affected product as a jump host.
Solution

[Update the Software]
Update the software to the latest version according to the information provided by the developer.
Vendor Information

XikeStor
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-88263
References

  1. JVN : JVN#45281119
Revision History

  • [2026/09/16]
      Web page was published