Description
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
Published: 2023-03-15
Score: 9.8 Critical
EPSS: 89.3% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Oct 2025 00:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Mon, 10 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2024-11-25'}


Mon, 02 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2024-11-25'}


Mon, 25 Nov 2024 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Mon, 25 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2024-11-25'}


Mon, 25 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Mon, 25 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
CPEs cpe:2.3:o:arraynetworks:arrayos_ag:-:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Arraynetworks Ag1000 Ag1000t Ag1000v5 Ag1100v5 Ag1150 Ag1200 Ag1200v5 Ag1500 Ag1500fips Ag1500v5 Ag1600 Ag1600v5 Arrayos Ag Vxag
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-10-21T23:15:23.174Z

Reserved: 2023-03-15T00:00:00.000Z

Link: CVE-2023-28461

cve-icon Vulnrichment

Updated: 2024-08-02T12:38:25.279Z

cve-icon NVD

Status : Analyzed

Published: 2023-03-15T23:15:10.070

Modified: 2025-11-03T18:14:11.060

Link: CVE-2023-28461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses