CVE-2023-28461
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Array Networks SSL VPN gateways (versions 9.4.0.481 and earlier) allow attackers to browse files on the server and execute code remotely without logging in. This happens through a weakness in how the product handles certain HTTP headers, making it critical to patch immediately.
CVE-2023-28461 is an unauthenticated remote code execution vulnerability in Array Networks Array AG Series and vxAG affecting versions ≤9.4.0.481. The attack vector exploits improper validation of a flags attribute in HTTP headers (CWE-306: Missing Authentication Check) to achieve filesystem access and code execution. Pre-condition is network access to the SSL VPN gateway; the impact includes complete system compromise via remote code execution.
The full analysis of this CVE is available in Portuguese →