CVE-2023-28461
KEV RANSOMWARECRITICAL 9.8EPSS 68.1%
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 68.08% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2024-11-25, used in ransomware campaigns
- Nuclei
- critical · CWE-306
- Published
- 2023-03-15
- Updated
- 2026-08-05