A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.