Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
No PoCs from references.
- https://github.com/Ostorlab/KEV
- https://github.com/packetinside/CISA_BOT
- https://github.com/ums91/CISA_BOT