NA

CVE-2023-35803

Published: 04/10/2023 Updated: 10/10/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

IQ Engine prior to 10.6r2 on Extreme Network AP devices has a Buffer Overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

extremenetworks iq_engine

Github Repositories

PoC Exploit for CVE-2023-35803 Unauthenticated Buffer Overflow in Aerohive HiveOS/Extreme Networks IQ Engine

CVE-2023-35803 - Unauthenticated RCE in Extreme Networks/Aerohive Wireless Access Points PoC for ARM-based access points running HiveOS/IQ Engine <106r2 Edit revshell to point to your shell catcher IP/port Host the reverse shell: python3 -m httpserver Open a shell catcher: nc -lvnp 1337 Run the POC (may take a few minutes): python3 pocpy <ip of ap> &qu