In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://www.exsiliumsecurity.com/CVE-2024-27453.html | third party advisory exploit |
https://extreme-networks.my.site.com/ExtrArticleDetail?an=000118266 | vendor advisory |