CVE-2020-18305: High severity extreme networks extremeware xos vulnerability
Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-18305?
CVE-2020-18305 is rated as a medium severity vulnerability due to its potential for sensitive information disclosure and privilege escalation.
How do I fix CVE-2020-18305?
To mitigate CVE-2020-18305, upgrade Extreme Networks EXOS to version 22.7 or later, or 30.2 or later.
What types of attacks can exploit CVE-2020-18305?
CVE-2020-18305 can be exploited by attackers to gain unauthorized access to sensitive information or escalate user privileges.
Which versions of Extreme Networks EXOS are affected by CVE-2020-18305?
CVE-2020-18305 affects Extreme Networks EXOS versions prior to 22.7 and 30.2.
Is there a workaround for CVE-2020-18305 if I cannot upgrade?
Currently, there are no documented workarounds for CVE-2020-18305; upgrading to a patched version is recommended.