An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privileges via crafted HTTP request.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExtremenetworks Exos
OSExtremenetworks< 22.731.0 – 31.7.1 (excl.)32.0 – 32.5.1.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-43119CRITICAL9.8PL ✓same product
Extreme Networks EXOS — privilege escalation przez Redis i Telnet
CVE-2023-43118HIGH8.8same product
Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS)...
CVE-2023-43121HIGH7.5same product
A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) ...
CVE-2013-7309MEDIUM5.4same product
The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID ...
CVE-2024-38292CRITICAL9.8PL ✓same vendor
Path traversal w Extreme Networks XIQ-SE umożliwiający privilege escalation