EXPOSURES › CVE-2023-28461
CVE-2023-28461
CRITICAL ⌖ ON CISA KEV · EXPLOITEDArray Networks AG/vxAG ArrayOS suffered a missing authentication vulnerability allowing attackers to read local files and execute code on the SSL VPN gateway.
The missing authentication for critical function vulnerability in Array Networks AG/vxAG ArrayOS allows attackers to read local files and execute code on the SSL VPN gateway, enabling remote code execution and compromising the system. This failure is critical for DIB organizations because it directly violates CMMC/NIST 800-171 requirements for protecting information systems and could lead to data breaches or ransomware attacks. Organizations must ensure all Array Networks AG/vxAG ArrayOS systems are patched and monitored for exploitation.
Shame score — The vulnerability allows remote code execution and file reading on an SSL VPN gateway, which is a critical security control, and is actively exploited in the wild, indicating severe negligence in patching and security management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.