PT-2023-4077 · Extreme Networks · Iq Engine

Lachlan Davidson

·

Published

2023-03-13

·

Updated

2023-10-10

·

CVE-2023-35803

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IQ Engine versions prior to 10.6r2
Description The issue is related to a buffer overflow in the IQ Engine service of Extreme Network AP devices, which can be exploited by a remote attacker to elevate privileges and execute arbitrary code.
Recommendations For IQ Engine versions prior to 10.6r2, update to version 10.6r2 or later to resolve the issue.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-04377
CVE-2023-35803
ZDI-23-1017

Affected Products

Iq Engine