PoC Index

CVE-2023-28461

KEV RANSOMWARECRITICAL 9.8EPSS 68.1%

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
68.08% chance of exploitation in the next 30 days, 99th percentile
CISA KEV
added 2024-11-25, used in ransomware campaigns
Nuclei
critical · CWE-306
Published
2023-03-15
Updated
2026-08-05

Nuclei templates (1)

References

Related