Vulnerability Description
A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing unauthorized access to network fabric and configuration data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Extremenetworks | Fabric Engine \(Voss\) | < 9.3 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-11192?
CVE-2025-11192 is a vulnerability with a CVSS score of 8.6 (HIGH). A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating I...
How severe is CVE-2025-11192?
CVE-2025-11192 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-11192?
Check the references section above for vendor advisories and patch information. Affected products include: Extremenetworks Fabric Engine \(Voss\).