CVE-2023-46271

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 19, 2025
Updated: Feb 20, 2025
CWE ID 120

Summary

CVE-2023-46271 is a buffer overflow vulnerability affecting Extreme Networks IQ Engine versions before 10.6r1a and through 10.6r4, up to 10.6r5. This issue resides in the ah_webui service, which is the default listener on TCP port 3009. Exploitation of this vulnerability could result in arbitrary code execution, posing a significant threat to network security. Attackers could utilize this flaw to gain unauthorized access to the affected system or cause denial-of-service conditions. It is strongly advised that users update their IQ Engine software to the latest patch level to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share