Junglewise Threat Intelligence

CVE-2023-28461: Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

CVE-2023-28461 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-11-25

Executive brief

Array Networks AG and vxAG ArrayOS contain a missing authentication vulnerability that allows remote attackers to browse the filesystem and execute code. Attackers can exploit this by using a flags attribute in an HTTP header to access local files on the SSL VPN gateway without authentication.

Affected products

  • Array Networks Array AG Series 9.4.0.481 and earlier
  • Array Networks vxAG 9.4.0.481 and earlier
  • Array Networks ArrayOS AG 9.4.0.481 and earlier

Timeline

  • 2023-03-09: advisory: Vendor advisory stated a fix would be available soon.
  • 2024-11-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.