Challenge-response Authorization Flaw in Extreme Networks' ExtremeXOS
CVE-2026-8169
What is CVE-2026-8169?
ExtremeXOS contains a vulnerability in its challenge-response mechanism, where the challenge value is generated from an insufficiently random source. This weakness can allow attackers to predict expected responses under certain circumstances, granting unauthorized access to the debug-mode function. If exploited, this could lead to the escalation of privileges to root-level access and allow persistent modifications to the device's software stack. Exploitation demands either a valid low-privilege account remotely or physical access through the serial console locally.
Affected Version(s)
Switch Engine (EXOS) Switch Engine 0 < 31.7.4
Switch Engine (EXOS) Switch Engine 32.0.0 < 32.7.4.15
Switch Engine (EXOS) Switch Engine 33.0.0 < 33.1.100
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
