9.8

CVE-2023-35802

IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ExtremenetworksIq Engine Version < 10.6r1
   ExtremenetworksAp122 Version-
   ExtremenetworksAp130 Version-
   ExtremenetworksAp150w Version-
   ExtremenetworksAp250 Version-
   ExtremenetworksAp30 Version-
   ExtremenetworksAp3000 Version-
   ExtremenetworksAp3000x Version-
   ExtremenetworksAp302w Version-
   ExtremenetworksAp305c Version-
   ExtremenetworksAp305c-1 Version-
   ExtremenetworksAp305cx Version-
   ExtremenetworksAp4000 Version-
   ExtremenetworksAp4000-1 Version-
   ExtremenetworksAp410c Version-
   ExtremenetworksAp410c-1 Version-
   ExtremenetworksAp460c Version-
   ExtremenetworksAp460s12c Version-
   ExtremenetworksAp460s6c Version-
   ExtremenetworksAp5010 Version-
   ExtremenetworksAp5050d Version-
   ExtremenetworksAp5050u Version-
   ExtremenetworksAp510c Version-
   ExtremenetworksAp510cx Version-
   ExtremenetworksAp630 Version-
   ExtremenetworksAp650 Version-
   ExtremenetworksAp650x Version-
ExtremenetworksIq Engine Version < 10.6r5
   ExtremenetworksAp1130 Version-
   ExtremenetworksAp550 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.77% 0.855
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.