CVE-2023-43119: Critical severity extreme networks extremeware xos vulnerability
Published Oct 16, 2023
·Updated
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.
Affected Software
3 affected components
Extremenetworks Exos<22.7
Extremenetworks Exos>=31.7.0<31.7.2
Extremenetworks Exos>=32.0<32.5.1.5
Event History
Oct 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
08:15 PM
Description
Frequently Asked Questions
1
What is CVE-2023-43119?
CVE-2023-43119 is an Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5.
2
How severe is CVE-2023-43119?
CVE-2023-43119 has a severity rating of 9.8 (critical).
3
What software versions are affected by CVE-2023-43119?
CVE-2023-43119 affects versions up to and including 22.7, 31.7.0 to 31.7.2, and 32.0 to 32.5.1.5 of Extreme Networks Switch Engine (EXOS).
4
What is the impact of CVE-2023-43119?
CVE-2023-43119 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.
5
How can I fix CVE-2023-43119?
To fix CVE-2023-43119, update Extreme Networks Switch Engine (EXOS) to version 32.5.1.5 or later.