#VU79021 Stack-based buffer overflow in Extreme Networks products - CVE-2023-35803

 

#VU79021 Stack-based buffer overflow in Extreme Networks products - CVE-2023-35803

Published: August 7, 2023 / Updated: August 7, 2023


Vulnerability identifier: #VU79021
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2023-35803
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available
Vulnerable software:
AP302W
AP305C/CX
AP305C-1
AP410C
AP410C-1
AP460C
AP460S6C
AP460S12C
AP510C/CX
AP630
AP650
AP650X
AP3000
AP3000X
AP4000
AP4000-1
AP5010
AP5050D
AP5050U
AP30
AP122
AP122X
AP130
AP150W
AP230
AP245X
AP250
AP550
AP1130
IQ Engine
Software vendor:
Extreme Networks

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the ah_acsd service. A remote attacker on the local network can trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links