{"id":"CVE-2025-11192","title":"A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered","summary":"A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-W…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-287"],"vendor":"extremenetworks","product":"fabric_engine_(voss)","affected":["fabric_engine_(voss) < 9.3"],"patched":["fabric_engine_(voss) 9.3"],"published":"2025-10-07","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:10:00.563","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11192","references":[{"url":"https://extreme-networks.my.site.com/ExtrArticleDetail?an=000130291","label":"1c053176-eef3-4d6a-ae0b-24728c86587b"}],"tags":["nvd"],"epss":0.00347,"epssPercentile":0.26123,"ingestedAt":"2026-10-08T22:11:53.798Z","slug":"CVE-2025-11192","body":"## Overview\n\nA vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing unauthorized access to network fabric and configuration data.\n\n## Affected\n\n- `fabric_engine_(voss) < 9.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fabric_engine_(voss) 9.3`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}