PT-2025-41159 · Extreme Networks · Fabric Engine

Published

2025-10-07

·

Updated

2025-10-07

·

CVE-2025-11192

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Extreme Networks Fabric Engine (VOSS) versions prior to 9.3
Description A flaw exists in Extreme Networks’ Fabric Engine (VOSS) where, when SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. This could allow unauthorized access to network fabric and configuration data by malicious actors. The SD-WAN AutoSense implementation is the affected component.
Recommendations Update to version 9.3 or later.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-11192

Affected Products

Fabric Engine