{"id":"CVE-2023-28461","title":"Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution","summary":"Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-287","CWE-306"],"vendor":"arraynetworks","product":"arrayos_ag","affected":["arrayos_ag <= 9.4.0.481"],"published":"2023-03-15","updated":"2026-08-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-28461","references":[{"url":"https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf","label":"cve@mitre.org"},{"url":"https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28461","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.68079,"epssPercentile":0.99293,"kev":true,"kevDateAdded":"2024-11-25","kevDueDate":"2024-12-16","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-05T05:45:57.495Z","slug":"CVE-2023-28461","body":"## Overview\n\nArray Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated \"a new Array AG release with the fix will be available soon.\"\n\n## Affected\n\n- `arrayos_ag <= 9.4.0.481`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":98,"depthScoreParts":{"impact":53.9,"likelihood":13.6,"exploitation":25,"ransomware":5},"changes":[]}