CVE-2023-46271
CRITICALExtreme Networks IQ Engine <10.6r5 - Buffer Overflow
Title source: llmDescription
Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default.
References (3)
Core 3
Core References
Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-23-1766/
Various Sources
https://extreme-networks.my.site.com/ExtrArticleDetail?an=000115354&q=CVE-2023-46271
Various Sources
https://extremenetworks.com
Scores
CVSS v3
9.8
EPSS
0.0010
EPSS Percentile
26.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-120
Status
published
Published
Feb 19, 2025
Tracked Since
Feb 18, 2026