Back

CRITICAL KEV Used in ransomware campaigns

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution

Published Mar 15, 2023 ·Due Dec 16, 2024

Description

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Mar 15, 2023
Updated Aug 5, 2026
Reserved Mar 15, 2023

CISA Vulnrichment

Updated Nov 26, 2024

NVD

Status Analyzed
Modified Aug 5, 2026

Red Hat

No data

ENISA EUVD

Assigner mitre
Published Mar 15, 2023
Updated Aug 5, 2026
Exploited since Nov 25, 2024

GitHub

No data