CVE-2025-11192: Fabric Engine (VOSS) AutoSense Authentication Bypass

Published Oct 7, 2025
·
Updated

A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing unauthorized access to network fabric and configuration data.

Affected Software

1 affected component
Extremenetworks Fabric Engine \(voss\)<9.3

Remediation

Information

Fixed in 9.3 or later.

Event History

Oct 7, 2025
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-11192?

CVE-2025-11192 is classified with a severity rating that could potentially allow unauthorized access due to the improper validation of ISIS authentication settings.

2

How do I fix CVE-2025-11192?

To fix CVE-2025-11192, upgrade Extreme Networks Fabric Engine (VOSS) to version 9.3 or later where the vulnerability is patched.

3

Which versions of Extreme Networks Fabric Engine (VOSS) are affected by CVE-2025-11192?

CVE-2025-11192 affects all versions of Extreme Networks Fabric Engine (VOSS) prior to version 9.3.

4

What can happen if CVE-2025-11192 is exploited?

If exploited, CVE-2025-11192 could allow an attacker to configure fabric connectivity without appropriate authentication checks, potentially compromising the network.

5

Is SD-WAN AutoSense safe to use with CVE-2025-11192 vulnerability?

Using SD-WAN AutoSense on affected versions of Extreme Networks Fabric Engine (VOSS) is not safe due to the risk of improper configuration without validation of authentication settings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203