CVE-2025-11192: Fabric Engine (VOSS) AutoSense Authentication Bypass
A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing unauthorized access to network fabric and configuration data.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11192?
CVE-2025-11192 is classified with a severity rating that could potentially allow unauthorized access due to the improper validation of ISIS authentication settings.
How do I fix CVE-2025-11192?
To fix CVE-2025-11192, upgrade Extreme Networks Fabric Engine (VOSS) to version 9.3 or later where the vulnerability is patched.
Which versions of Extreme Networks Fabric Engine (VOSS) are affected by CVE-2025-11192?
CVE-2025-11192 affects all versions of Extreme Networks Fabric Engine (VOSS) prior to version 9.3.
What can happen if CVE-2025-11192 is exploited?
If exploited, CVE-2025-11192 could allow an attacker to configure fabric connectivity without appropriate authentication checks, potentially compromising the network.
Is SD-WAN AutoSense safe to use with CVE-2025-11192 vulnerability?
Using SD-WAN AutoSense on affected versions of Extreme Networks Fabric Engine (VOSS) is not safe due to the risk of improper configuration without validation of authentication settings.