216.73.217.98

CVE-2025-6083

· Published 13/06/2025 21:15 · Modified 13/06/2025 22:15

Labels: CVE-2025-6083 1c053176-eef3-4d6a-ae0b-24728c86587b2025-06-13CVE-2025-6083CWE-287

Essential information

Published
13/06/2025 21:15
Modified
13/06/2025 22:15
Author
Creator
CVSS
5.2 MEDIUM (v3) 5.2 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

In ExtremeCloud Universal ZTNA, a syntax error in the 'searchKeyword' condition caused queries to bypass the owner_id filter. This issue may allow users to search data across the entire table instead of being restricted to their specific owner_id.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
1c053176-eef3-4d6a-ae0b-24728c86587b
NVD
View on NVD

Affected products (CPE)

ProductCPE
extreme networks / extremecloud universal ztna cpe:2.3:a:extreme_networks:extremecloud_universal_ztna:*:*:*:*:*:*:*:*

References