Stack-based buffer overflow in Extreme Networks products - CVE-2023-35803

 

Stack-based buffer overflow in Extreme Networks products - CVE-2023-35803

Published: August 7, 2023 / Updated: August 7, 2023


Vulnerability identifier: #VU79021
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-35803
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the ah_acsd service. A remote attacker on the local network can trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

AP4000
AP1130
AP550
AP250
AP245X
AP230
AP150W
AP130
AP122X
AP122
AP30
AP5050U
AP5050D
AP5010
AP4000-1
AP302W
AP3000X
AP3000
AP650X
AP650
AP630
AP510C/CX
AP460S12C
AP460S6C
AP460C
AP410C-1
AP410C
AP305C-1
AP305C/CX
IQ Engine

How to mitigate CVE-2023-35803

Install updates from vendor's website.

IQ Engine - addressed in versions 10.6r2, 10.6r5

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins