Crafted HTTP POST Request Can Escalate Privileges to Root in Extreme XOS
CVE-2024-27453

Currently unrated

Key Information:

Vendor
CVE Published:
3 May 2024

What is CVE-2024-27453?

In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).

References

Timeline

  • Vulnerability published

.
CVE-2024-27453 : Crafted HTTP POST Request Can Escalate Privileges to Root in Extreme XOS