CVE-2023-28461
Description
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
Summary dbcve.org
Array Networks SSL VPN gateways (Array AG Series and vxAG versions 9.4.0.481 and earlier) contain an authentication bypass vulnerability allowing unauthenticated attackers to browse the filesystem via a flags attribute in an HTTP header. This filesystem access can be chained with a separate vulnerable URL to achieve remote code execution.
Mitigation
Apply the vendor-provided firmware/security update as soon as available; until then, restrict network access to the SSL VPN management interface to trusted IP addresses only.