---
id: CVE-2025-11192
title: >-
  A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was
  discovered
summary: >-
  A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was
  discovered. When SD-WAN AutoSense is enabled on a port, it may automatically
  configure fabric connectivity without validating ISIS authentication settings.
  The SD-W…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-287
vendor: extremenetworks
product: fabric_engine_(voss)
affected:
  - fabric_engine_(voss) < 9.3
patched:
  - fabric_engine_(voss) 9.3
published: '2025-10-07'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11192'
references:
  - url: 'https://extreme-networks.my.site.com/ExtrArticleDetail?an=000130291'
    label: 1c053176-eef3-4d6a-ae0b-24728c86587b
tags:
  - nvd
epss: 0.00347
epssPercentile: 0.26123
ingestedAt: '2026-10-08T22:11:53.798Z'
---

## Overview

A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing unauthorized access to network fabric and configuration data.

## Affected

- `fabric_engine_(voss) < 9.3`

## Remediation

Upgrade past the affected range:

- `fabric_engine_(voss) 9.3`
