Known Vulnerabilities for products from Extremenetworks

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Extremenetworks".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Extremenetworks can be found at device.report : Extremenetworks

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-0689 json In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an a... Not Provided 2026-03-02 2026-06-05
CVE-2023-43121 json A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5... 7.5 - HIGH 2023-10-16 2023-10-27
CVE-2023-43120 json An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers ... 8.8 - HIGH 2023-10-16 2023-10-24
CVE-2023-43119 json An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allow... 9.8 - CRITICAL 2023-10-16 2023-10-27
CVE-2023-43118 json Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.... 8.8 - HIGH 2023-10-16 2023-10-27
CVE-2023-35803 json IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow. 9.8 - CRITICAL 2023-10-04 2023-10-10
CVE-2023-35802 json IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that... 9.8 - CRITICAL 2023-07-15 2023-07-26
CVE-2020-16847 json Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET... 6.1 - MEDIUM 2020-08-04 2020-08-11
CVE-2020-16152 json The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a a... 9.8 - CRITICAL 2021-11-14 2021-11-18
CVE-2020-13820 json Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request. 6.1 - MEDIUM 2020-08-03 2023-11-07
CVE-2020-13819 json Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request. 6.1 - MEDIUM 2020-08-05 2020-08-06
CVE-2018-5797 json An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smi... 7.5 - HIGH 2018-02-05 2019-10-03
CVE-2018-5787 json An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remo... 7.5 - HIGH 2018-02-05 2020-08-24
CVE-2017-14332 json Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values. Not Provided 2017-10-23 2025-04-20
CVE-2017-14331 json Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain... Not Provided 2017-10-23 2025-04-20
CVE-2017-14330 json Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process. Not Provided 2017-10-23 2025-04-20
CVE-2017-14329 json Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell. Not Provided 2017-10-23 2025-04-20
CVE-2017-14328 json Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot. Not Provided 2017-10-23 2025-04-20
CVE-2017-14327 json Extreme EXOS 16.x, 21.x, and 22.x allows administrators to read arbitrary files. Not Provided 2017-10-23 2025-04-20
CVE-2013-7309 json The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link ... Not Provided 2014-01-23 2026-04-29

Known software with vulnerabilities from Extremenetworks

Type Vendor Product Version
HardwareExtremenetworksAlpine-
HardwareExtremenetworksBlackdiamond 10808-
HardwareExtremenetworksBlackdiamond 8800-
Operating
System
ExtremenetworksExos-
Operating
System
ExtremenetworksExtremeware Xos-
Operating
System
ExtremenetworksExtremewireless Wing5.0
Operating
System
ExtremenetworksExtremexos15.3.5
ApplicationExtremenetworksExtreme Management Center8.4.1.24
HardwareExtremenetworksMsm64-
HardwareExtremenetworksSummit-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report