The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password.
The authentication mechanism of the built-in web server does not completely verify user identity, resulting in the ability to bypass the password entry stage. A remote, unauthenticated attacker, without requiring user interaction or meeting additional conditions, can successfully authenticate to the device's web interface. The vulnerability is classified as CWE-1390 (Weak Authentication), indicating a fundamental flaw in the identity verification process logic.
An attacker gains unauthorized access to the network switch management interface, which may enable them to read and modify device configuration, thereby threatening the confidentiality and integrity of the entire network infrastructure managed by the switch.
Patches available from the manufacturer should be applied in accordance with references — detailed information about versions containing the fix is available in the CISA advisory ICSA-24-275-01 at https://www.cisa.gov/news-events/ics-advisories/icsa-24-275-01. Until the patch is deployed, it is recommended to restrict access to the device's web interface only to trusted management networks (e.g., through a firewall or dedicated management VLAN).
ONS-S8 Spectra Aggregation Switch device — specific firmware versions indicated in manufacturer references (advisory ICSA-24-275-01 published by CISA)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X