Impact
The mv, cp, and rm utilities in the ExtremeXOS (EXOS) shell do not properly canonicalize paths (CWE‑59), allowing attackers with low‑privilege CLI access to create symbolic links that reference privileged filesystem locations. By executing the affected utilities, an attacker can read, modify, or replace security‑critical files outside their authorized scope, potentially gaining root‑level access and inserting persistent modifications into the device software stack. This flaw compromises confidentiality, integrity, and, in some cases, availability of the network device.
Affected Systems
The vulnerability affects Extreme Networks Switch Engine (EXOS) devices running any releases prior to the fixed builds 31.7.4, 32.7.4.15, 33.1.100, or 33.7.1.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the KEV catalog. Exploitation can occur remotely by a low‑privilege user who has CLI access, or locally via the serial console. The attack path involves creating a malicious symlink and then invoking the vulnerable utilities to manipulate privileged files.
OpenCVE Enrichment