Executive brief
Array Networks AG and vxAG ArrayOS contain a missing authentication vulnerability that allows remote attackers to browse the filesystem and execute code. Attackers can exploit this by using a flags attribute in an HTTP header to access local files on the SSL VPN gateway without authentication.
Affected products
- Array Networks Array AG Series 9.4.0.481 and earlier
- Array Networks vxAG 9.4.0.481 and earlier
- Array Networks ArrayOS AG 9.4.0.481 and earlier
Timeline
- 2023-03-09: advisory: Vendor advisory stated a fix would be available soon.
- 2024-11-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.