← All CVEs

CVE-2023-28461

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added 2024-11-25Remediation due 2024-12-16

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

9.8
CVSS
68.1%
EPSS (exploit prob.)
99th
EPSS percentile
2023-03-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-287CWE-306

Affected products

VendorProductAffected versions
arraynetworksarrayos_ag<= 9.4.0.481
arraynetworksag1000all versions
arraynetworksag1000tall versions
arraynetworksag1000v5all versions
arraynetworksag1100v5all versions
arraynetworksag1150all versions
arraynetworksag1200all versions
arraynetworksag1200v5all versions
arraynetworksag1500all versions
arraynetworksag1500fipsall versions
arraynetworksag1500v5all versions
arraynetworksag1600all versions
arraynetworksag1600v5all versions
arraynetworksvxagall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-28461