CVE-2017-14329: High severity extreme networks exos vulnerability
Published Oct 23, 2017
·Updated
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell.
Affected Software
17 affected components
Extremenetworks Extremexos=15.7
Extremenetworks Extremexos=16.1.2
Extremenetworks Extremexos=16.1.3
Extremenetworks Extremexos=16.1.4
Extremenetworks Extremexos=16.2
Extremenetworks Extremexos=16.2.2
Extremenetworks Extremexos=16.2.3
Extremenetworks Extremexos=16.2.4
Extremenetworks Extremexos=21.1
Extremenetworks Extremexos=21.1.1
Extremenetworks Extremexos=21.1.2
Extremenetworks Extremexos=21.1.3
Extremenetworks Extremexos=21.1.4
Extremenetworks Extremexos=22.1
Extremenetworks Extremexos=22.2
Extremenetworks Extremexos=22.3
Extremenetworks Extremexos=22.4
Event History
Oct 23, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14329?
CVE-2017-14329 is classified as a high severity vulnerability due to the ability for an unauthorized user to gain root access.
2
How do I fix CVE-2017-14329?
To mitigate CVE-2017-14329, upgrade to a patched version of Extreme EXOS that does not allow unauthorized access to the debug shell.
3
Which versions are affected by CVE-2017-14329?
CVE-2017-14329 affects Extreme EXOS versions 15.7, 16.x, 21.x, and 22.x.
4
What can happen if I am vulnerable to CVE-2017-14329?
If vulnerable to CVE-2017-14329, an attacker could gain full root access to the system, potentially compromising sensitive data and control.
5
Is there a workaround for CVE-2017-14329?
No official workaround is suggested for CVE-2017-14329; the recommended approach is to apply the necessary patches.