Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Fixed in 9.3 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 15 Jan 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Extremenetworks
Extremenetworks fabric Engine \(voss\) |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:o:extremenetworks:fabric_engine_\(voss\):*:*:*:*:*:*:*:* | |
| Vendors & Products |
Extremenetworks
Extremenetworks fabric Engine \(voss\) |
|
| Metrics |
cvssV3_1
|
Wed, 08 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Oct 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Extreme Networks
Extreme Networks fabric Engine |
|
| Vendors & Products |
Extreme Networks
Extreme Networks fabric Engine |
Tue, 07 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing unauthorized access to network fabric and configuration data. | |
| Title | Fabric Engine (VOSS) AutoSense Authentication Bypass | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ExtremeNetworks
Published:
Updated: 2025-10-08T15:45:56.015Z
Reserved: 2025-09-30T13:38:06.105Z
Link: CVE-2025-11192
Updated: 2025-10-08T15:45:48.917Z
Status : Analyzed
Published: 2025-10-07T19:15:33.863
Modified: 2026-01-15T02:10:58.137
Link: CVE-2025-11192
No data.
OpenCVE Enrichment
Updated: 2025-10-08T13:35:20Z