Executive brief
AOS-CX network switches contain a vulnerability in their API endpoint that allows attackers to bypass authentication controls without credentials. This could let unauthorized actors gain administrative access to switches used to manage corporate networks, potentially enabling network disruption, data theft, or lateral movement to other systems.
Technical details
An authentication bypass vulnerability exists in the API endpoint of Arista AOS-CX switches, allowing an unauthenticated remote attacker to circumvent authentication controls. The vulnerability is network-accessible and requires no user interaction or prior authentication. An attacker exploiting this flaw could gain unauthorized access to the switch's API, potentially leading to administrative control, configuration changes, or information disclosure. Patches are available from Arista/HPE support.
Affected products
- Arista AOS-CX
Timeline
- 2026-09-01: disclosed