CRITICAL

CVE-2023-28461

Arraynetworks Arrayos Ag 2023-03-15 CVSS v3.1
CVSS
9.8
KEV

Description

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

Summary dbcve.org

Array Networks SSL VPN gateways (Array AG Series and vxAG versions 9.4.0.481 and earlier) contain an authentication bypass vulnerability allowing unauthenticated attackers to browse the filesystem via a flags attribute in an HTTP header. This filesystem access can be chained with a separate vulnerable URL to achieve remote code execution.

Mitigation

Apply the vendor-provided firmware/security update as soon as available; until then, restrict network access to the SSL VPN management interface to trusted IP addresses only.

Weakness (CWE)

CWE-287 Improper Authentication
CWE-306 Missing Authentication

EPSS Score

68.08%
Probability of exploitation in next 30 days
99.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE