PT-2023-21734 · Array Networks · Array Ag Series+1
CVE-2023-28461
·
Publicado
2023-03-15
·
Atualizado
2026-08-05
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Array Networks Array AG Series and vxAG versions 9.4.0.481 and earlier
Description
A critical security flaw allows remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. There is evidence of active exploitation of this issue.
Recommendations
For versions 9.4.0.481 and earlier, upgrade to version 9.4.0.484 or later immediately.
As a temporary workaround, consider restricting access to the vulnerable URL and disabling the use of HTTP header flags until a patch is available.
Apply mitigations to protect your organization from cyberattacks by visiting the CISA website for more information.
Correção
RCE
Missing Authentication
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Array Ag Series
Vxag