CVE-2023-28461
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Added 2024-11-25Remediation due 2024-12-16
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
9.8
CVSS
68.1%
EPSS (exploit prob.)
99th
EPSS percentile
2023-03-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287CWE-306
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| arraynetworks | arrayos_ag | <= 9.4.0.481 |
| arraynetworks | ag1000 | all versions |
| arraynetworks | ag1000t | all versions |
| arraynetworks | ag1000v5 | all versions |
| arraynetworks | ag1100v5 | all versions |
| arraynetworks | ag1150 | all versions |
| arraynetworks | ag1200 | all versions |
| arraynetworks | ag1200v5 | all versions |
| arraynetworks | ag1500 | all versions |
| arraynetworks | ag1500fips | all versions |
| arraynetworks | ag1500v5 | all versions |
| arraynetworks | ag1600 | all versions |
| arraynetworks | ag1600v5 | all versions |
| arraynetworks | vxag | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf
- https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28461
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-28461