Vulnerability record · CVE-2023-28461 · published 15 March 2023
CVE-2023-28461: Array Networks ArrayOS AG SSL VPN missing authentication allows RCE
Arraynetworks · Arrayos Ag
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) permit unauthenticated remote code execution. An attacker can browse the filesystem of the SSL VPN gateway via a flags attribute in an HTTP header, then exploit a vulnerable URL. This is a critical pre-auth flaw on an internet-facing VPN gateway, a class of device heavily targeted for initial access.
Description
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE on an internet-facing SSL VPN, with CVSS 9.8, KEV listing and known ransomware use.
What it is
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) permit unauthenticated remote code execution. An attacker can browse the filesystem of the SSL VPN gateway via a flags attribute in an HTTP header, then exploit a vulnerable URL. This is a critical pre-auth flaw on an internet-facing VPN gateway, a class of device heavily targeted for initial access.
Impact
An unauthenticated attacker gains remote code execution on the SSL VPN gateway, with high impact to confidentiality, integrity and availability. Full control of the gateway can expose internal network access and credentials handled by the device.
Attack surface
Reached over the network via HTTP requests to the SSL VPN gateway; the CVSS vector (AV:N/PR:N/UI:N) and CWE-306 indicate no authentication and no user interaction are required. The header-based filesystem browsing is the reconnaissance step before triggering the vulnerable URL.
Exploitation
Listed in CISA KEV (added 2024-11-25) with known ransomware campaign use, and EPSS 30-day probability is 0.68 (99.3rd percentile), indicating active exploitation. No public exploit references are included in the record beyond the vendor advisory and KEV entry.
What to do
- Apply the fixed Array AG release from the vendor advisory; the 2023-03-09 notice stated a new release would be available soon, so confirm the current fixed version with Array Networks.
- If no fix can be applied, follow CISA KEV guidance and discontinue use of the affected product.
- Restrict management and VPN portal access to trusted networks or IP allowlists and remove direct internet exposure where feasible.
- Monitor the vendor advisory page for updated mitigation instructions and validate the running firmware version against the fixed release.
Detection
- Inspect HTTP requests to the SSL VPN gateway for unusual or attacker-controlled flags attributes in headers.
- Alert on requests to unexpected or malformed URLs on the gateway that deviate from normal VPN portal traffic.
- Review gateway and web logs for filesystem enumeration patterns or anomalous access preceding exploitation attempts.
- Hunt for post-exploitation activity on the gateway host, including unexpected processes, files or outbound connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-28461 to the Known Exploited Vulnerabilities catalog on 25 November 2024 as "Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 16 December 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_ | MitigationVendor Advisory |
| https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_ | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28461 | US Government Resource |
Track CVE-2023-28461 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-28461), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.