PT-2023-21734 · Array Networks · Array Ag Series+1

CVE-2023-28461

·

Publicado

2023-03-15

·

Atualizado

2026-08-05

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Array Networks Array AG Series and vxAG versions 9.4.0.481 and earlier
Description A critical security flaw allows remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. There is evidence of active exploitation of this issue.
Recommendations For versions 9.4.0.481 and earlier, upgrade to version 9.4.0.484 or later immediately. As a temporary workaround, consider restricting access to the vulnerable URL and disabling the use of HTTP header flags until a patch is available. Apply mitigations to protect your organization from cyberattacks by visiting the CISA website for more information.

Correção

RCE

Missing Authentication

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28461

Produtos afetados

Array Ag Series
Vxag