CVE-2023-28461criticalunder attackransomwareCWE-306

CVE-2023-28461

Published · Updated

70Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 9.8epss 68%
from disclosure to weapon
Published on NVDMar 15
CISA KEV+621d
exploitation probability
68%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2024-12-16

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

Array Networks SSL VPN gateways (versions 9.4.0.481 and earlier) allow attackers to browse files on the server and execute code remotely without logging in. This happens through a weakness in how the product handles certain HTTP headers, making it critical to patch immediately.

Technical detail

CVE-2023-28461 is an unauthenticated remote code execution vulnerability in Array Networks Array AG Series and vxAG affecting versions ≤9.4.0.481. The attack vector exploits improper validation of a flags attribute in HTTP headers (CWE-306: Missing Authentication Check) to achieve filesystem access and code execution. Pre-condition is network access to the SSL VPN gateway; the impact includes complete system compromise via remote code execution.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a