Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2023-46273 is a stack-based buffer overflow vulnerability (CWE-121) in the Bonjour Gateway component of Extreme Networks IQ Engine. The vulnerability exists in the ah_event_send function, where insufficient input validation allows an attacker to overflow a buffer and potentially execute arbitrary code. This affects IQ Engine versions before 10.6r1a and 10.6r2 through 10.6r4, impacting network infrastructure administrators and organizations relying on Extreme Networks equipment for network management and visibility. With a CVSS score of 8.8, this is a high-severity vulnerability that could allow remote code execution on affected systems, compromising network security monitoring capabilities and potentially enabling lateral movement within enterprise environments.
While this specific CVE currently has no direct MITRE ATT&CK technique mapping and shows zero matching Casky skills, organizations using Casky.ai can leverage Claude's extended reasoning capabilities to investigate related attack patterns. Practitioners should monitor for exploitation attempts by examining network traffic patterns to the Bonjour Gateway service, analyzing system logs for unusual ah_event_send function calls with oversized payloads, and detecting anomalous process execution or privilege escalation following suspicious gateway communications. The absence of mapped skills highlights a critical gap: upgrading to IQ Engine 10.6r5 or later is essential while security teams implement network segmentation around management interfaces and monitor for indicators of compromise associated with buffer overflow exploitation techniques like code injection and process memory corruption.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2023-46273. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation