Impact
The weakness lies in the use of an insufficiently random source when generating the challenge value for the debug‑mode authentication. An attacker who can predict or brute‑force the challenge can supply a valid response, allowing and potentially elevating privileges to root on the device. The ability to modify the software stack persistently escalates a low‑privilege account remotely or by accessing the serial console locally.
Affected Systems
Extreme Networks Switch Engine (EXOS) systems are impacted. The CVE affects firmware releases earlier than 31.7.4, 32.7.4.15, 33.1.100, and 33.7.1. These older releases are found on devices running earlier ExtremeXOS firmware.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, is not listed in the CISA KEV catalogue, and its EPSS score is less than 1%. Exploitation requires the presence of a low‑privilege account or direct physical console access, but the remote scenario remains realistic for environments where the device is accessible over the network. Because the flaw enables root‑level access and potential persistent changes, the risk of compromise is high, especially if an attacker can target untrusted users or physically reach the console.
OpenCVE Enrichment