Skip to main content

Vendor archive

extremenetworks CVEs

Beta · best-effort

30 CVEs tagged to vendor extremenetworks5 Critical, 12 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2026-0689

Published Mar 2, 2026

In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitiv…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11192

Published Oct 7, 2025

A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-8679

Published Oct 1, 2025

In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6235

Published Jul 21, 2025

In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handlin…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38292

Published Feb 27, 2025

In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38290

Published Feb 27, 2025

In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-18305

Published May 14, 2024

Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27453

Published May 3, 2024

In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43121

Published Oct 16, 2023

A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and before 31.7.2 allows attackers to r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43119

Published Oct 16, 2023

An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-43118

Published Oct 16, 2023

Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 32.5.1.5 allows attackers to ru…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43120

Published Oct 16, 2023

An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privileges via crafted HTTP request.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16152

Published Nov 14, 2021

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user v…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5797

Published Feb 5, 2018

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES Key that can be used for pack…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5787

Published Feb 5, 2018

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Stack Overflow in the RIM (Radio I…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14332

Published Oct 23, 2017

Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14331

Published Oct 23, 2017

Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14330

Published Oct 23, 2017

Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2