Extremenetworks
Extremenetworks IQ Engine: vulnerabilidades y CVE
Extremenetworks IQ Engine tiene 5 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses1
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-46273 | Alta (8.8) | 0.31% | — | 14 sept 2026 | Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send. |
| CVE-2023-46272 | Alta (8.8) | 0.40% | — | 19 feb 2025 | Buffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute arbitrary code via the implementation of the ah_auth service |
| CVE-2023-46271 | Crítica (9.8) | 0.76% | — | 19 feb 2025 | Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default. |
| CVE-2023-35803 | Crítica (9.8) | 1.6% | — | 4 oct 2023 | IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow. |
| CVE-2023-35802 | Crítica (9.8) | 1.1% | — | 15 jul 2023 | IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.