Home

Description

A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing unauthorized access to network fabric and configuration data.

PUBLISHED Reserved 2025-09-30 | Published 2025-10-07 | Updated 2025-10-08 | Assigner ExtremeNetworks




HIGH: 8.4CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N

Problem types

CWE-287 Improper Authentication

Product status

Default status
unaffected

9.2
affected

References

extreme-networks.my.site.com/ExtrArticleDetail?an=000130291

cve.org (CVE-2025-11192)

nvd.nist.gov (CVE-2025-11192)

Download JSON