PromptRiskDBThreat intelligence atlas

CVE-2023-28461 - Array Networks AG/vxAG ArrayOS

AI Vulnerability Context

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

Overview

A source-backed snapshot of this vulnerability.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVCRITICAL
CVE ID
CVE-2023-28461
Vendor/project
Array Networks
Product
AG/vxAG ArrayOS
Vulnerability name
Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
Date added
2024-11-25
Due date
2024-12-16
Known ransomware campaign use
Known
CVSS v3
9.8
CWE-306

Exploit context

What the vulnerability is about.

No description available. The source record only contains identifiers and metadata.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.