Impact
The vulnerability is a classic stack buffer overflow in the ah_bgd buffer triggered by the ah_event_send functionality. A crafted payload that corrupts the stack and potentially execute arbitrary code with the privileges of the IQ Engine process, thereby compromising confidentiality, integrity, and availability of the affected device. It is inferred that such code execution is possible based on the description of the overflow, though the exact payload capability is not detailed.
Affected Systems
Extreme Networks IQ Engine devices running versions before 10.6r5, including all editions from 10.6r1a through 10.6r4, are affected. The vulnerability resides in the Bonjour Gateway component of IQ Engine.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity vulnerability; the EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The flaw is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is through network traffic directed at the Bonjour Gateway service, so any host exposed to that interface could be at risk.
OpenCVE Enrichment