Extreme Networks ExtremeCloud IQ - Site Engine NAC Admin Credential Exposure Vulnerability
Vulnerability
A vulnerability exists in the NAC administration interface of ExtremeCloud IQ - Site Engine (XIQ-SE) versions prior to 26.2.10. This vulnerability allows authenticated NAC administrators to access masked sensitive information, such as credential values, from HTTP responses. Although the user interface redacts these credentials, the application inadvertently reveals the actual values in the response, enabling administrators to retrieve stored secrets that may exceed their authorized access.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive credentials, allowing an administrator to gain access to information or resources beyond their intended permissions.
Remediation
Users can upgrade to ExtremeCloud IQ - Site Engine version 26.2.10 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
