Buffer Overflow Vulnerability in Extreme Networks IQ Engine
CVE-2023-46272

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
19 February 2025

What is CVE-2023-46272?

A buffer overflow vulnerability in Extreme Networks IQ Engine can occur due to flaws in the implementation of the ah_auth service. This vulnerability may allow an attacker to execute arbitrary code by sending malicious input to the affected versions, specifically those prior to 10.6r1a and between 10.6r4, before 10.6r5. It is crucial for users of this software to ensure their systems are updated to patch this vulnerability and mitigate potential risks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-46272 : Buffer Overflow Vulnerability in Extreme Networks IQ Engine