Known Vulnerabilities for products from Extremenetworks
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Extremenetworks".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Additional devices specifications by Extremenetworks can be found at device.report : Extremenetworks
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-0689 json | In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an a... | Not Provided | 2026-03-02 | 2026-06-05 |
| CVE-2023-43121 json | A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5... | 7.5 - HIGH | 2023-10-16 | 2023-10-27 |
| CVE-2023-43120 json | An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers ... | 8.8 - HIGH | 2023-10-16 | 2023-10-24 |
| CVE-2023-43119 json | An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allow... | 9.8 - CRITICAL | 2023-10-16 | 2023-10-27 |
| CVE-2023-43118 json | Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.... | 8.8 - HIGH | 2023-10-16 | 2023-10-27 |
| CVE-2023-35803 json | IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow. | 9.8 - CRITICAL | 2023-10-04 | 2023-10-10 |
| CVE-2023-35802 json | IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that... | 9.8 - CRITICAL | 2023-07-15 | 2023-07-26 |
| CVE-2020-16847 json | Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET... | 6.1 - MEDIUM | 2020-08-04 | 2020-08-11 |
| CVE-2020-16152 json | The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a a... | 9.8 - CRITICAL | 2021-11-14 | 2021-11-18 |
| CVE-2020-13820 json | Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request. | 6.1 - MEDIUM | 2020-08-03 | 2023-11-07 |
| CVE-2020-13819 json | Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request. | 6.1 - MEDIUM | 2020-08-05 | 2020-08-06 |
| CVE-2018-5797 json | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smi... | 7.5 - HIGH | 2018-02-05 | 2019-10-03 |
| CVE-2018-5787 json | An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remo... | 7.5 - HIGH | 2018-02-05 | 2020-08-24 |
| CVE-2017-14332 json | Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values. | Not Provided | 2017-10-23 | 2025-04-20 |
| CVE-2017-14331 json | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain... | Not Provided | 2017-10-23 | 2025-04-20 |
| CVE-2017-14330 json | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process. | Not Provided | 2017-10-23 | 2025-04-20 |
| CVE-2017-14329 json | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell. | Not Provided | 2017-10-23 | 2025-04-20 |
| CVE-2017-14328 json | Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot. | Not Provided | 2017-10-23 | 2025-04-20 |
| CVE-2017-14327 json | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to read arbitrary files. | Not Provided | 2017-10-23 | 2025-04-20 |
| CVE-2013-7309 json | The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link ... | Not Provided | 2014-01-23 | 2026-04-29 |
Known software with vulnerabilities from Extremenetworks
| Type | Vendor | Product | Version |
|---|---|---|---|
| Hardware | Extremenetworks | Alpine | - |
| Hardware | Extremenetworks | Blackdiamond 10808 | - |
| Hardware | Extremenetworks | Blackdiamond 8800 | - |
| Operating System | Extremenetworks | Exos | - |
| Operating System | Extremenetworks | Extremeware Xos | - |
| Operating System | Extremenetworks | Extremewireless Wing | 5.0 |
| Operating System | Extremenetworks | Extremexos | 15.3.5 |
| Application | Extremenetworks | Extreme Management Center | 8.4.1.24 |
| Hardware | Extremenetworks | Msm64 | - |
| Hardware | Extremenetworks | Summit | - |