CVE-2025-11192 - CVE House
Back to Database
Status published High CVE-2025-11192

Fabric Engine (VOSS) AutoSense Authentication Bypass

Vulnerability Description

A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is enabled on a port, it may automatically configure fabric connectivity without validating ISIS authentication settings. The SD-WAN AutoSense implementation may be exploited by malicious actors by allowing unauthorized access to network fabric and configuration data.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11192

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Extreme Networks

View all reports →

Affected Software

Fabric Engine (VOSS)
Vulnerable Versions:
9.2

Timeline

Official Publish: October 7th, 2025
Last Modified: October 8th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)