IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Extremenetworks
Subscribe
|
Ap1130
Subscribe
Ap122
Subscribe
Ap130
Subscribe
Ap150w
Subscribe
Ap250
Subscribe
Ap30
Subscribe
Ap3000
Subscribe
Ap3000x
Subscribe
Ap302w
Subscribe
Ap305c
Subscribe
Ap305c-1
Subscribe
Ap305cx
Subscribe
Ap4000
Subscribe
Ap4000-1
Subscribe
Ap410c
Subscribe
Ap410c-1
Subscribe
Ap460c
Subscribe
Ap460s12c
Subscribe
Ap460s6c
Subscribe
Ap5010
Subscribe
Ap5050d
Subscribe
Ap5050u
Subscribe
Ap510c
Subscribe
Ap510cx
Subscribe
Ap550
Subscribe
Ap630
Subscribe
Ap650
Subscribe
Ap650x
Subscribe
Iq Engine
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-39797 | IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:extremenetworks:iq_engine:-:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-30T18:24:42.767Z
Reserved: 2023-06-17T00:00:00
Link: CVE-2023-35802
Updated: 2024-08-02T16:30:45.237Z
Status : Modified
Published: 2023-07-15T02:15:08.803
Modified: 2024-11-21T08:08:44.367
Link: CVE-2023-35802
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD