LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-28461: Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 25, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Dec 16, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-28461 to its Known Exploited Vulnerabilities catalog on Nov 25, 2024, with a federal patch deadline of Dec 16, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.

CVE-2023-28461 is a missing authentication for critical function vulnerability in Array Networks AG and vxAG ArrayOS. It allows an unauthenticated attacker to read local files and execute code on the SSL VPN gateway. Because this product class sits at the network edge and the vulnerability is known to be used by ransomware operators, unpatched gateways present a direct path for initial access and follow-on compromise.

Defenders should treat any internet-facing Array Networks SSL VPN instance as high priority until the vendor-recommended mitigations are confirmed in place or the product is removed from service.

How it works

The underlying weakness is CWE-306: missing authentication for a critical function. In this case, certain functions on the Array Networks AG/vxAG ArrayOS SSL VPN gateway do not properly require authentication before allowing sensitive operations. An attacker who can reach the gateway can therefore invoke those functions without credentials.

According to the CISA summary, successful abuse lets the attacker read local files on the device and execute code. Exact request formats, endpoints, or payload details are not provided here; treat any unauthenticated access to administrative or diagnostic interfaces on these gateways as potentially exploitable and confirm the precise attack surface against the vendor advisory.

Am I affected? How to find it in your systems

Array Networks AG and vxAG ArrayOS appliances commonly function as SSL VPN gateways, often placed at the perimeter to terminate remote-access sessions. Inventory every device that presents an Array Networks SSL VPN service, whether physical, virtual, or cloud-hosted.

How to remediate

The primary remediation is to apply the mitigations or updates specified by Array Networks for CVE-2023-28461. CISA’s required action is explicit: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor fix is installed, reduce exposure with compensating controls typical for missing-authentication flaws on edge VPN devices.

If your data may have been exposed

Actively exploited vulnerabilities of this class frequently lead to ransomware deployment and data theft. If logs or other indicators suggest compromise, assume the gateway and any systems reachable through it may have been accessed. Rotate credentials that traversed the VPN, examine connected hosts for lateral movement, and follow your incident-response plan. You can also run a free exposure scan of your email addresses to check whether related credentials or personal data already appear in known breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedArray Networks · AG/vxAG ArrayOS
WeaknessCWE-306
Added to CISA KEVNov 25, 2024
Federal patch deadlineDec 16, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities