CVE-2023-28461
Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 16 December 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 68.08% probability · 99th percentile
- CISA KEV
- Listed 25 November 2024 · due 16 December 2024 · used in ransomware campaigns
- Weakness
- CWE-287, CWE-306
- Affected
- arraynetworks/arrayos ag
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2023-28461
References
- https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdfMitigation, Vendor Advisory
- https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdfMitigation, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28461US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.