Executive brief
The Bonjour Gateway daemon in Extreme Networks IQ Engine (HiveOS), which manages wireless access points, contains a stack-based buffer overflow vulnerability. An attacker can exploit this by sending crafted messages to the daemon, leading to arbitrary code execution with root privileges, potentially compromising entire network infrastructure and all connected wireless devices.
Technical details
A stack-based buffer overflow exists in the ah_bgd (Bonjour Gateway daemon) service within Extreme Networks IQ Engine. An attacker can invoke the vulnerable ah_event_send function with a crafted event_id and event_message parameter, triggering the overflow condition. The vulnerability affects the ah_scd daemon which is also vulnerable to stack-based buffer overflow, allowing an attacker to execute arbitrary code as root. The issue has been patched in version 10.6r1a or later for older AP models and 10.6r5 or later for newer models. This is a network-accessible vulnerability with no apparent authentication requirement.
Affected products
- Extreme Networks IQ Engine before 10.6r1a, and 10.6r1a through 10.6r4 before 10.6r5
Timeline
- 2023-09-14: disclosed: CVE-2023-46273 published
- 2023-12-05: advisory: Extreme Networks SA-2023-135 security advisory released
- 2023: patched: Fixed in IQ Engine 10.6r1a for certain AP models, and 10.6r5 for others