CVE-2023-46273
Received Received - Intake

Bonjour Gateway Buffer Overflow in Extreme Networks IQ Engine

Vulnerability report for CVE-2023-46273, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: MITRE

Description

Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
extreme_networks bonjour_gateway to 10.6r5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow vulnerability in the Bonjour Gateway daemon (ah_bgd) of Extreme Networks IQ Engine. It occurs when the 'ah_event_send' function processes a specially crafted 'event_id' and 'event_message', potentially allowing arbitrary code execution with root privileges.

Detection Guidance

Detection involves checking the version of Extreme Networks IQ Engine Bonjour Gateway. Use commands like 'show version' or 'show system' on affected devices to verify if the installed version is below 10.6r1a or 10.6r5, depending on the model.

Impact Analysis

An attacker could exploit this to execute malicious code on the affected device with root privileges, leading to unauthorized access, data theft, or disruption of network services. Systems running vulnerable IQ Engine versions are at risk.

Mitigation Strategies

Immediately upgrade the IQ Engine Bonjour Gateway to version 10.6r1a or later for supported models, or 10.6r5 or later for others. Ensure no unsupported or end-of-life products are in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-46273. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart