SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-28461

Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

KEVCRITICAL 9.8EPSS 68.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 16 December 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
68.08% probability · 99th percentile
CISA KEV
Listed 25 November 2024 · due 16 December 2024 · used in ransomware campaigns
Weakness
CWE-287, CWE-306
Affected
arraynetworks/arrayos ag
Source
cve@mitre.org

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf ; https://nvd.nist.gov/vuln/detail/CVE-2023-28461

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.