PT-2023-9082 · Extreme Networks · Extreme Networks Iq Engine+1

Victorien Molle

·

Published

2023-12-12

·

Updated

2025-02-20

·

CVE-2023-46271

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Extreme Networks IQ Engine versions prior to 10.6r1a Extreme Networks IQ Engine versions 10.6r1a through 10.6r4 before 10.6r5 Extreme Networks AP410C (affected versions not specified)
Description The issue arises from the ah webui service, which listens on TCP port 3009 by default. It is related to deficiencies in the authentication procedure of the ah webui service in Extreme Networks AP410C network switch microcode. This allows a remote attacker to bypass existing security restrictions. The vulnerability can be exploited by network-adjacent attackers to reach critical functions on affected installations of Extreme Networks AP410C routers without requiring authentication.
Recommendations For Extreme Networks IQ Engine versions prior to 10.6r1a, update to version 10.6r1a or later. For Extreme Networks IQ Engine versions 10.6r1a through 10.6r4 before 10.6r5, update to version 10.6r5 or later. For Extreme Networks AP410C, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the ah webui service to minimize the risk of exploitation.

Improper Authentication

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-03481
CVE-2023-46271
ZDI-23-1766

Affected Products

Extreme Networks Ap410C
Extreme Networks Iq Engine