Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2025-11192 A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically… Fabric Engine \(voss\) 9.3+ Fix from $1,9502025-10-07 CRITICAL 9.8 CVE-2025-8679 In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest … Extremeguest Essentials 25.5.0+ Fix from $2,3002025-10-01 MEDIUM 6.1 CVE-2025-6235 In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The iss… Extremecontrol 25.5.12+ Fix from $1,6002025-07-21 CRITICAL 9.8 CVE-2024-38292 In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalatio… Xiq Se 24.2.11+ Fix from $2,3002025-02-27 HIGH 8.8 CVE-2024-38291 In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation. Xiq Se 24.2.11+ Fix from $1,9502025-02-27 MEDIUM 5.3 CVE-2024-38290 In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met. Xiq Se 24.2.11+ Fix from $1,6002025-02-27 HIGH 8.0 CVE-2020-18305 Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing … Extremexos 22.7+ Fix from $1,9502024-05-14 HIGH 8.6 CVE-2024-27453 In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine… Extremexos 22.7+ Fix from $1,9502024-05-03 CRITICAL 9.8 CVE-2023-43119 An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain esca… Exos 22.7 / 31.7.2+ Fix from $2,3002023-10-16 HIGH 8.8 CVE-2023-43118 Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 3… Exos 31.7.2 / 32.5.1.5+ Fix from $1,9502023-10-16 HIGH 7.5 CVE-2023-43121 A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and befor… Exos 22.7 / 31.7.2+ Fix from $1,9502023-10-16 HIGH 8.8 CVE-2023-43120 An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privil… Exos 22.7 / 31.7.1+ Fix from $1,9502023-10-16 CRITICAL 9.8 CVE-2023-35803 IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow. Iq Engine 10.6r2 / 10.6r5+ Fix from $2,3002023-10-04 CRITICAL 9.8 CVE-2023-35802 IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obt… Iq Engine 10.6r1 / 10.6r5+ Fix from $2,3002023-07-15 CRITICAL 9.8 CVE-2020-16152EPSS 35% The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execu… Aerohive Netconfig 10.0r8a+ Fix from $2,3002021-11-14 MEDIUM 6.1 CVE-2020-13819 Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request. Extreme Management Center 8.5.0.169+ Fix from $1,6002020-08-05 MEDIUM 6.1 CVE-2020-16847 Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887. Extreme Management Center 8.5.0.169+ Fix from $1,6002020-08-04 MEDIUM 6.1 CVE-2020-13820 Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request. Extreme Management Center Mitigation only Fix from $1,6002020-08-03 HIGH 7.5 CVE-2018-5787 An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Stac… Extremewireless Wing 5.8.6.9 / 5.9.1.3+ Fix from $1,9502018-02-05 HIGH 7.5 CVE-2018-5797 An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES… Extremewireless Wing 5.8.6.9 / 5.9.1.3+ Fix from $1,9502018-02-05 HIGH 8.1 CVE-2017-14332 Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values. Extremexos Mitigation only Fix from $1,9502017-10-23 HIGH 7.5 CVE-2017-14328 Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot. Extremexos Mitigation only Fix from $1,9502017-10-23 MEDIUM 6.7 CVE-2017-14329 Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell. Extremexos Mitigation only Fix from $1,6002017-10-23 MEDIUM 6.7 CVE-2017-14330 Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process. Extremexos No fix yet Fix from $1,6002017-10-23 MEDIUM 6.7 CVE-2017-14331 Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell. Extremexos Mitigation only Fix from $1,6002017-10-23 MEDIUM 5.4 CVE-2013-7309 The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA… Exos Mitigation only Fix from $1,6002014-01-23