Impact
XikeStor Layer3 switches allow an attacker to download configuration data without authentication, exposing network settings and stored passwords. This flaw enables the attacker to gain detailed operational knowledge of the device and potentially use the device as a launch point into internal networks, thereby compromising confidentiality and enabling lateral movement.
Affected Systems
The vulnerability affects XikeStor Layer3 switch models SKS8300-12E2T2X, SKS8300-8T, and SKS8310-8X. No specific firmware or software version ranges are identified in the advisory.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low likelihood of public exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is network‑based access to the management interface, allowing an unauthenticated attacker to retrieve configuration files.
OpenCVE Enrichment