CVE-2023-35802: Buffer Overflow
IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-35802.
What is the title of the vulnerability?
The title of the vulnerability is 'IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of CAPWAP protocol'.
What is the severity level of CVE-2023-35802?
The severity level of CVE-2023-35802 is critical with a score of 9.8.
How can the vulnerability be exploited?
The vulnerability can be exploited by obtaining access to the internal management interface/subnet.
Where can I find more information about CVE-2023-35802?
You can find more information about CVE-2023-35802 at the following link: https://extremeportal.force.com/ExtrArticleDetail?an=000112741.