|
[Japanese]
|
JVNDB-2026-000134
|
XikeStor Layer3 switches miss authentication for downloading configuration data
|
XikeStor Layer3 switches contain the vulnerability listed below.- Missing authentication for downloading configuration (CWE-306) - CVE-2026-88263
|
CVSS V3 Severity: Base Metrics 7.5 (High) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
|
CVSS v4 Severity
Base Metrics: 8.7 (High) [IPA Score]
- Access Vector (AV): Network
- Attack Complexity (AC): Low
- Attack Requirements (AT): None
- Privileges Required (PR): None
- User Interaction (UI): None
Vulnerable System Impact
- Confidentiality Impact (VC): High
- Integrity Impact (VI): None
- Availability Impact (VA): None
Subsequent System Impact
- Confidentiality Impact (SC): None
- Integrity Impact (SI): None
- Availability Impact (SA): None
|
|
XikeStor
- SKS8300-12E2T2X versions prior to V1.04.B09
- SKS8300-8T versions prior to V1.04.B09
- SKS8310-8X versions prior to V1.04.B09
|
|
Confidential information, such as network configurations or passwords, may be retrieved by an unauthenticated attacker.
This allows the attacker to operate the affected product improperly or to exploit the affected product as a jump host.
|
[Update the Software]
Update the software to the latest version according to the information provided by the developer.
|
XikeStor
|
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2026-88263
|
- JVN : JVN#45281119
|
- [2026/09/16]
Web page was published
|