CVE-2024-27453: Extremenetworks Extremexos
High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).
Affected products
- Extremenetworks Extremexos: before 22.7 (fixed in 22.7)
Published 2024-05-03. Last modified 2026-06-17.