IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit.
References
Link | Resource |
---|---|
https://extremeportal.force.com/ExtrArticleDetail?an=000112741 | Vendor Advisory |
https://extremeportal.force.com/ExtrArticleDetail?an=000112741 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
No history.
Information
Published : 2023-07-15 02:15
Updated : 2024-11-21 08:08
NVD link : CVE-2023-35802
Mitre link : CVE-2023-35802
CVE.ORG link : CVE-2023-35802
JSON object : View
Products Affected
extremenetworks
- ap5010
- ap510c
- ap30
- ap305c-1
- ap1130
- ap305c
- ap130
- ap550
- ap630
- ap4000-1
- ap150w
- ap410c-1
- ap510cx
- ap250
- iq_engine
- ap5050d
- ap410c
- ap5050u
- ap460s12c
- ap3000
- ap650x
- ap4000
- ap460c
- ap122
- ap302w
- ap460s6c
- ap305cx
- ap650
- ap3000x
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')