rray Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
Configuration 1 (hide)
| AND |
|
03 Nov 2025, 18:14
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28461 - US Government Resource |
22 Oct 2025, 00:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Feb 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf - Mitigation, Vendor Advisory |
02 Dec 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf - Mitigation, Vendor Advisory |
25 Nov 2024, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-306 |
25 Nov 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-862 |
21 Nov 2024, 07:55
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf - Mitigation, Vendor Advisory |
Published : 2023-03-15 23:15
Updated : 2025-11-03 18:14
NVD link : CVE-2023-28461
Mitre link : CVE-2023-28461
CVE.ORG link : CVE-2023-28461
JSON object : View