Extreme would like to thank Hadrien Barral (Université Gustave Eiffel) and Georges-Axel Jaloyan (French Ministry of the Interior) for responsible disclosure of their findings.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
Extreme Networks has released fixed versions of Switch Engine (EXOS) that address this vulnerability. Customers should upgrade to one of the following releases or later: 31.7.4, 32.7.4.15, 33.1.100, or 33.7.1.
Workaround
Where immediate upgrade is not feasible, customers should: (1) restrict CLI access to trusted administrators only; (2) enforce strong authentication and rotate any default credentials; (3) restrict physical access to serial console ports; and (4) monitor device logs for unexpected debug-mode activation attempts.
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Extreme Networks
Extreme Networks switch Engine (exos) |
|
| Vendors & Products |
Extreme Networks
Extreme Networks switch Engine (exos) |
Mon, 20 Jul 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under certain conditions may allow an attacker to predict the expected response and activate debug-mode without authorization. Depending on device configuration and version, this may enable escalation to root-level access and persistent modification of the device software stack. Exploitation requires either a valid low-privilege account on the device (remote scenario) or physical serial console access (local scenario). This vulnerability is distinct from CVE-2017-14329, which addressed a different issue involving Python script privileges. | ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under certain conditions may allow an attacker to predict the expected response and activate debug-mode without authorization. Depending on device configuration and version, this may enable escalation to root-level access and persistent modification of the device software stack. Exploitation requires either a valid low-privilege account on the device (remote scenario) or physical serial console access (local scenario). This vulnerability is distinct from CVE-2017-14329, which addressed a different issue involving Python script privileges. Extreme would like to thank Hadrien Barral (Université Gustave Eiffel) and Georges-Axel Jaloyan (French Ministry of the Interior) for responsible disclosure of their findings. |
Mon, 20 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under certain conditions may allow an attacker to predict the expected response and activate debug-mode without authorization. Depending on device configuration and version, this may enable escalation to root-level access and persistent modification of the device software stack. Exploitation requires either a valid low-privilege account on the device (remote scenario) or physical serial console access (local scenario). This vulnerability is distinct from CVE-2017-14329, which addressed a different issue involving Python script privileges. | |
| Title | ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG | |
| Weaknesses | CWE-338 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ExtremeNetworks
Published:
Updated: 2026-07-20T19:20:47.552Z
Reserved: 2026-05-08T12:59:08.619Z
Link: CVE-2026-8169
Updated: 2026-07-20T18:26:13.494Z
Status : Awaiting Analysis
Published: 2026-07-20T18:16:56.420
Modified: 2026-07-21T20:25:45.920
Link: CVE-2026-8169
No data.
OpenCVE Enrichment
Updated: 2026-07-30T19:00:09Z