Extreme Networks, Inc.

First CVE: Jun 13, 2025Active for: 1 year
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
4.0
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Extreme Networks, Inc. as a CNA, 62.5% affect products that Extreme Networks, Inc. develops as a vendor.

62.5%
37.5%
Self-reported: 5Third-party: 3

Of all the CVEs published that affect products developed by Extreme Networks, Inc., 16.7% are self-published by Extreme Networks, Inc. as a CNA.

16.7%
83.3%
Self-published: 5Published by other CNAs: 25

Trends Over Time

The number and severity of CVEs published by Extreme Networks, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 13, 2025
13 months ago
Most Recent CVE
Jul 20, 2026
4 days ago

Top CVEs

All CVEs published by Extreme Networks, Inc. as a CNA, regardless of affected vendor or product.

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privile
Jul 20, 20268.737NONO
ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random sou
Jul 20, 20268.736NONO
In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure. Under certain ExtremeGuest Essentials captive-portal SSID
Oct 1, 20259.830NONO
A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests
May 29, 20266.329NONO
A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity
Oct 7, 20258.626NONO
In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling
Jul 21, 20256.118NONO
In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive
Mar 2, 20264.917NONO
In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the e
Jun 13, 20254.315NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA8 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low4 (50.0%)
High1 (12.5%)
None3 (37.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Extreme Networks, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Extreme Networks, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs