VendorsExtremenetworksextremexosall versions
Vulnerabilities

Extremenetworks Extreme Networks ExtremeXOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-27453
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).
Published 2024-05-03 · Analyzed
8.6EPSS 0.007
CVE-2017-14332
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values.
Published 2017-10-23 · Modified
8.1EPSS 0.010
CVE-2020-18305
Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges.
Published 2024-05-13 · Analyzed
8.0EPSS 0.007
CVE-2017-14328
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot.
Published 2017-10-23 · Modified
7.8EPSS 0.013
CVE-2017-14331
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell.
Published 2017-10-23 · Modified
7.2EPSS 0.004
CVE-2017-14330
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.
Published 2017-10-23 · Modified
7.2EPSS 0.003
CVE-2017-14329
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell.
Published 2017-10-23 · Modified
7.2EPSS 0.003
CVE-2017-14327
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to read arbitrary files.
Published 2017-10-23 · Modified
4.9EPSS 0.003