← Vulnerability feed

Vulnerability record · CVE-2023-28461 · published 15 March 2023

CVE-2023-28461: Array Networks ArrayOS AG SSL VPN missing authentication allows RCE

Arraynetworks · Arrayos Ag

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) permit unauthenticated remote code execution. An attacker can browse the filesystem of the SSL VPN gateway via a flags attribute in an HTTP header, then exploit a vulnerable URL. This is a critical pre-auth flaw on an internet-facing VPN gateway, a class of device heavily targeted for initial access.

9.8 CVSS 3.1 Critical CISA KEV since 25 Nov 2024 Known ransomware use EPSS 68% · top 0.7% CWE-287 · Improper authenticationCWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score
68%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
5 Aug 2026Last modified by NVD

Description

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE on an internet-facing SSL VPN, with CVSS 9.8, KEV listing and known ransomware use.

What it is

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) permit unauthenticated remote code execution. An attacker can browse the filesystem of the SSL VPN gateway via a flags attribute in an HTTP header, then exploit a vulnerable URL. This is a critical pre-auth flaw on an internet-facing VPN gateway, a class of device heavily targeted for initial access.

Impact

An unauthenticated attacker gains remote code execution on the SSL VPN gateway, with high impact to confidentiality, integrity and availability. Full control of the gateway can expose internal network access and credentials handled by the device.

Attack surface

Reached over the network via HTTP requests to the SSL VPN gateway; the CVSS vector (AV:N/PR:N/UI:N) and CWE-306 indicate no authentication and no user interaction are required. The header-based filesystem browsing is the reconnaissance step before triggering the vulnerable URL.

Exploitation

Listed in CISA KEV (added 2024-11-25) with known ransomware campaign use, and EPSS 30-day probability is 0.68 (99.3rd percentile), indicating active exploitation. No public exploit references are included in the record beyond the vendor advisory and KEV entry.

What to do

  • Apply the fixed Array AG release from the vendor advisory; the 2023-03-09 notice stated a new release would be available soon, so confirm the current fixed version with Array Networks.
  • If no fix can be applied, follow CISA KEV guidance and discontinue use of the affected product.
  • Restrict management and VPN portal access to trusted networks or IP allowlists and remove direct internet exposure where feasible.
  • Monitor the vendor advisory page for updated mitigation instructions and validate the running firmware version against the fixed release.

Detection

  • Inspect HTTP requests to the SSL VPN gateway for unusual or attacker-controlled flags attributes in headers.
  • Alert on requests to unexpected or malformed URLs on the gateway that deviate from normal VPN portal traffic.
  • Review gateway and web logs for filesystem enumeration patterns or anomalous access preceding exploitation attempts.
  • Hunt for post-exploitation activity on the gateway host, including unexpected processes, files or outbound connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-28461 to the Known Exploited Vulnerabilities catalog on 25 November 2024 as "Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 16 December 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-28461 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-66644Array Networks ArrayOS AG command injection exploited in the wildArrayOS AG before 9.4.5.9 contains an OS command injection flaw (CWE-78) that is reachable over the network without authentication. It has been explo…KEVEPSS 3.4%analysed9.8CVE-2023-51707Arraynetworks arrayos ag command injection vulnerabilityMotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffe…EPSS 1.3%9.8CVE-2022-42897Arraynetworks arrayos ag command injection vulnerabilityArray Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of th…EPSS 1.6%7.5CVE-2023-41121Arraynetworks arrayos ag uncontrolled resource consumption vulnerabilityArray AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations.EPSS 0.84%4.9CVE-2023-24613Arraynetworks arrayos ag out-of-bounds write vulnerabilityThe user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite the backend …EPSS 0.79%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed

Source: NIST National Vulnerability Database (record CVE-2023-28461), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.