CVE-2020-18305: Extremenetworks Extremexos
High severity, CVSS 8.0. EPSS: 0.7% chance of exploitation in the next 30 days.
Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges.
Affected products
- Extremenetworks Extremexos: before 22.7 (fixed in 22.7); version 30.1 only
Published 2024-05-14. Last modified 2026-06-17.