ZeroHour

CVE-2023-28461

KEV ransomwaremoderate

Unauthenticated RCE in Array Networks AG/vxAG SSL VPN Gateways (ArrayOS)

CISA: Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

CVSS 3.1
9.8 critical
EPSS
68%p99
Published
()
KEV added
AI analysis

CVE-2023-28461 is a critical (CVSS 9.8) missing-authentication flaw in Array Networks' AG series and virtual vxAG SSL VPN gateways running ArrayOS 9.4.0.481 and earlier. An unauthenticated remote attacker sends an HTTP request to a vulnerable URL containing a 'flags' attribute in an HTTP header, which allows browsing the filesystem on the SSL VPN gateway; vendor and CERT reporting indicate this can be leveraged into full remote code execution, and JPCERT has confirmed active command-injection attacks. Successful exploitation gives the attacker code execution on the appliance, compromising the VPN gateway and potentially providing a foothold into the protected internal network. Any organization running an affected AG/vxAG gateway is exposed; these are enterprise SSL VPN appliances, with notable deployments in Japan and the wider Asia-Pacific region. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-25 (ransomware use known), JPCERT/CC reports widespread exploitation, Chinese-linked activity including MirrorFace targeting Japanese firms has been reported, and EPSS places the 30-day exploitation probability at 68.1%.

What to do: Upgrade AG/vxAG gateways to a fixed ArrayOS release per Array Networks' instructions — as of the 2023-03-09 advisory a fixed release was pending, so apply any release newer than 9.4.0.481 once available; if mitigations are unavailable, discontinue use per the CISA KEV required action, and federal agencies should follow CISA's directive to patch. Review gateway logs and downstream systems for signs of exploitation, and treat any compromised appliance as a potential network foothold given confirmed ransomware use.

Affected
Array Networks AG series and vxAG SSL VPN gateways (ArrayOS)9.4.0.481 and earlier
Estimated exposure
moderatelikely on the order of thousands (roughly 1,000–10,000) of internet-exposed AG/vxAG gateway appliances, each typically serving many remote users (estimate) — No public scan counts or install figures were provided in the available data, so this order-of-magnitude estimate is based on deployment patterns: internet-exposed enterprise SSL VPN appliances from a mid-sized vendor with concentrated…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

CISA Known Exploited Vulnerability
Affected
Array Networks AG/vxAG ArrayOS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
arraynetworks
Products
arrayos ag
Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news