CVE-2023-46273
largeBuffer Overflow in Extreme Networks IQ Engine Bonjour Gateway (ah_bgd)
Extreme Networks IQ Engine, the operating system running on Extreme (formerly Aerohive) access points and switches, contains a buffer overflow (CWE-121) in the Bonjour Gateway daemon (ah_bgd), reachable via the ah_event_send function. Bonjour Gateway relays Apple Bonjour/mDNS traffic between network segments, and because the CVSS 3.1 vector is network-reachable with low privileges required and no user interaction, an attacker with limited access to the network or device management plane can send crafted input that overflows the buffer and crashes or likely executes code on the affected AP or switch. Successful exploitation yields high impact to the confidentiality, integrity, and availability of the device. All IQ Engine releases before 10.6r1a, as well as 10.6r1a through 10.6r4, are affected, with the issue resolved in 10.6r5. The flaw is not on the CISA Known Exploited Vulnerabilities list, no public proof-of-concept exists, and no exploitation in the wild is known.
What to do: Upgrade IQ Engine to 10.6r5 or later, which remediates both affected branches (pre-10.6r1a and 10.6r1a through 10.6r4). If patching must be deferred, disable the Bonjour Gateway feature where it is not required and restrict which VLANs, client subnets, and management interfaces can interact with the Bonjour/mDNS gateway service. Monitor access points and switches for unexplained ah_bgd crashes or spontaneous device reboots, which can indicate exploitation attempts.
| Extreme Networks IQ Engine (Bonjour Gateway / ah_bgd) | before 10.6r1a; and 10.6r1a through 10.6r4 (i.e., all releases prior to 10.6r5) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.