CVE-2023-35803

IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:extremenetworks:iq_engine:*:*:*:*:*:*:*:*
OR cpe:2.3:h:extremenetworks:ap3000:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap3000x:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap302w:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap305c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap305c-1:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap305cx:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap4000:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap4000-1:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap410c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap410c-1:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap460c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap460s12c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap460s6c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap5010:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap5050d:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap5050u:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap510c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap510cx:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap630:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap650:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap650x:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:extremenetworks:iq_engine:*:*:*:*:*:*:*:*
OR cpe:2.3:h:extremenetworks:ap1130:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap122:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap130:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap150w:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap250:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap30:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap550:-:*:*:*:*:*:*:*

History

10 Oct 2023, 20:04

Type Values Removed Values Added
CWE CWE-120
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:h:extremenetworks:ap510c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap250:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap130:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap305c-1:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap150w:-:*:*:*:*:*:*:*
cpe:2.3:o:extremenetworks:iq_engine:*:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap3000x:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap302w:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap305cx:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap410c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap3000:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap460c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap410c-1:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap650:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap4000:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap650x:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap5050d:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap30:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap5050u:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap460s12c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap5010:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap122:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap550:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap460s6c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap4000-1:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap630:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap305c:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap510cx:-:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:ap1130:-:*:*:*:*:*:*:*
References (MISC) https://community.extremenetworks.com/t5/security-advisories-formerly/sa-2023-067-iq-engine-acsd-service-buffer-overflow-cve-2023/ba-p/96472 - (MISC) https://community.extremenetworks.com/t5/security-advisories-formerly/sa-2023-067-iq-engine-acsd-service-buffer-overflow-cve-2023/ba-p/96472 - Vendor Advisory
First Time Extremenetworks ap460c
Extremenetworks ap305c-1
Extremenetworks ap305cx
Extremenetworks ap4000
Extremenetworks ap122
Extremenetworks ap5050d
Extremenetworks ap130
Extremenetworks ap650x
Extremenetworks ap410c-1
Extremenetworks ap410c
Extremenetworks ap630
Extremenetworks
Extremenetworks ap5010
Extremenetworks ap30
Extremenetworks iq Engine
Extremenetworks ap510cx
Extremenetworks ap4000-1
Extremenetworks ap460s6c
Extremenetworks ap1130
Extremenetworks ap5050u
Extremenetworks ap510c
Extremenetworks ap305c
Extremenetworks ap550
Extremenetworks ap250
Extremenetworks ap3000
Extremenetworks ap150w
Extremenetworks ap3000x
Extremenetworks ap650
Extremenetworks ap302w
Extremenetworks ap460s12c

04 Oct 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-04 22:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-35803

Mitre link : CVE-2023-35803

CVE.ORG link : CVE-2023-35803


JSON object : View

Products Affected

extremenetworks

  • ap250
  • ap122
  • ap3000x
  • ap4000-1
  • ap5050d
  • ap650
  • ap1130
  • ap510c
  • ap150w
  • ap30
  • ap550
  • ap460c
  • ap4000
  • ap305cx
  • ap5050u
  • ap510cx
  • ap305c
  • ap460s12c
  • ap460s6c
  • ap5010
  • ap630
  • ap650x
  • ap410c-1
  • ap130
  • ap305c-1
  • ap410c
  • iq_engine
  • ap302w
  • ap3000
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')