Executive brief
Arista AOS-CX is a network operating system used in switches and routers to manage enterprise network infrastructure. An authenticated attacker can inject malicious scripts into the web-based management interface that execute when administrators access it, potentially allowing theft of admin credentials, unauthorized configuration changes, or network compromise.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the web-based management interface of AOS-CX. The vulnerability requires an authenticated attacker to inject malicious script code through the management interface; this code is then stored and executed in the browser context of administrative users who access the affected interface. An attacker with valid credentials can execute arbitrary JavaScript in an admin's session, potentially leading to session hijacking, credential theft, or unauthorized administrative actions. Patch availability should be confirmed through Arista/HPE support channels.
Affected products
- Arista AOS-CX
Timeline
- 2026-09-01: disclosed