Description
XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Configuration Retrieval
Action: Update Firmware
AI Analysis

Impact

XikeStor Layer3 switches allow an attacker to download configuration data without authentication, exposing network settings and stored passwords. This flaw enables the attacker to gain detailed operational knowledge of the device and potentially use the device as a launch point into internal networks, thereby compromising confidentiality and enabling lateral movement.

Affected Systems

The vulnerability affects XikeStor Layer3 switch models SKS8300-12E2T2X, SKS8300-8T, and SKS8310-8X. No specific firmware or software version ranges are identified in the advisory.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low likelihood of public exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is network‑based access to the management interface, allowing an unauthenticated attacker to retrieve configuration files.

Generated by OpenCVE AI on September 16, 2026 at 15:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware release from XikeStor to the affected switches
  • Configure the switches to require authentication before allowing configuration file downloads
  • Restrict management interface access to trusted network segments or IP addresses using firewall rules or access control lists

Generated by OpenCVE AI on September 16, 2026 at 15:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Download Configuration Data on XikeStor Layer3 Switches

Wed, 16 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected product improperly or to exploit the affected product as a jump host.
Weaknesses CWE-306
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-16T15:02:24.681Z

Reserved: 2026-09-10T00:56:14.741Z

Link: CVE-2026-88263

cve-icon Vulnrichment

Updated: 2026-09-16T15:02:18.383Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T08:16:40.303

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-88263

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:15:14Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function