Skip to main content

Vendor/product archive

extremenetworks / extremexos CVEs

Beta · best-effort

8 CVEs tagged to extremenetworks / extremexos0 Critical, 4 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2020-18305

Published May 14, 2024

Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27453

Published May 3, 2024

In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14332

Published Oct 23, 2017

Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14331

Published Oct 23, 2017

Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14330

Published Oct 23, 2017

Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14329

Published Oct 23, 2017

Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1