Stack-based buffer overflow in Extreme Networks products - CVE-2023-46272

 

Stack-based buffer overflow in Extreme Networks products - CVE-2023-46272

Published: January 4, 2024


Vulnerability identifier: #VU84983
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-46272
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
AP30
AP122
AP122X
AP130
AP150W
AP230
AP245X
AP250
AP550
AP1130
AP302W
AP305C/CX
AP305C-1
AP410C
AP410C-1
AP460C
AP460S6C
AP460S12C
AP510C/CX
AP630
AP650
AP650X
AP3000
AP3000X
AP4000
AP4000-1
AP5010
AP5050D
AP5050U
IQ Engine
Software vendor:
Extreme Networks

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the ah_auth service. A remote unauthenticated attacker on the local network can trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links