Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fabric Engine \(voss\) HIGH 8.6
CVE-2025-11192

A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically…

Fix: 9.3+
Fix from $1,950 2025-10-07
Extremeguest Essentials CRITICAL 9.8
CVE-2025-8679

In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest …

Fix: 25.5.0+
Fix from $2,300 2025-10-01
Extremecontrol MEDIUM 6.1
CVE-2025-6235

In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The iss…

Fix: 25.5.12+
Fix from $1,600 2025-07-21
Xiq Se CRITICAL 9.8
CVE-2024-38292

In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalatio…

Fix: 24.2.11+
Fix from $2,300 2025-02-27
Xiq Se HIGH 8.8
CVE-2024-38291

In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.

Fix: 24.2.11+
Fix from $1,950 2025-02-27
Xiq Se MEDIUM 5.3
CVE-2024-38290

In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.

Fix: 24.2.11+
Fix from $1,600 2025-02-27
Extremexos HIGH 8.0
CVE-2020-18305

Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing …

Fix: 22.7+
Fix from $1,950 2024-05-14
Extremexos HIGH 8.6
CVE-2024-27453

In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine…

Fix: 22.7+
Fix from $1,950 2024-05-03
Exos CRITICAL 9.8
CVE-2023-43119

An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain esca…

Fix: 22.7 / 31.7.2+
Fix from $2,300 2023-10-16
Exos HIGH 8.8
CVE-2023-43118

Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 3…

Fix: 31.7.2 / 32.5.1.5+
Fix from $1,950 2023-10-16
Exos HIGH 7.5
CVE-2023-43121

A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and befor…

Fix: 22.7 / 31.7.2+
Fix from $1,950 2023-10-16
Exos HIGH 8.8
CVE-2023-43120

An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privil…

Fix: 22.7 / 31.7.1+
Fix from $1,950 2023-10-16
Iq Engine CRITICAL 9.8
CVE-2023-35803

IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.

Fix: 10.6r2 / 10.6r5+
Fix from $2,300 2023-10-04
Iq Engine CRITICAL 9.8
CVE-2023-35802

IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obt…

Fix: 10.6r1 / 10.6r5+
Fix from $2,300 2023-07-15
Aerohive Netconfig CRITICAL 9.8
CVE-2020-16152EPSS 35%

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execu…

Fix: 10.0r8a+
Fix from $2,300 2021-11-14
Extreme Management Center MEDIUM 6.1
CVE-2020-13819

Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.

Fix: 8.5.0.169+
Fix from $1,600 2020-08-05
Extreme Management Center MEDIUM 6.1
CVE-2020-16847

Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.

Fix: 8.5.0.169+
Fix from $1,600 2020-08-04
Extreme Management Center MEDIUM 6.1
CVE-2020-13820

Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.

Mitigation only
Fix from $1,600 2020-08-03
Extremewireless Wing HIGH 7.5
CVE-2018-5787

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated Stac…

Fix: 5.8.6.9 / 5.9.1.3+
Fix from $1,950 2018-02-05
Extremewireless Wing HIGH 7.5
CVE-2018-5797

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES…

Fix: 5.8.6.9 / 5.9.1.3+
Fix from $1,950 2018-02-05
Extremexos HIGH 8.1
CVE-2017-14332

Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values.

Mitigation only
Fix from $1,950 2017-10-23
Extremexos HIGH 7.5
CVE-2017-14328

Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot.

Mitigation only
Fix from $1,950 2017-10-23
Extremexos MEDIUM 6.7
CVE-2017-14329

Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell.

Mitigation only
Fix from $1,600 2017-10-23
Extremexos MEDIUM 6.7
CVE-2017-14330

Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.

No fix yet
Fix from $1,600 2017-10-23
Extremexos MEDIUM 6.7
CVE-2017-14331

Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell.

Mitigation only
Fix from $1,600 2017-10-23
Exos MEDIUM 5.4
CVE-2013-7309

The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA…

Mitigation only
Fix from $1,600 2014-01-23