Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2023-51707

Disclosure Date: December 22, 2023 (last updated January 10, 2024)
MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected.
Attacker Value
Unknown

CVE-2023-41121

Disclosure Date: August 25, 2023 (last updated October 08, 2023)
Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations.
Attacker Value
Unknown

CVE-2023-28461

Disclosure Date: March 15, 2023 (last updated October 08, 2023)
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."
Attacker Value
Unknown

CVE-2023-28460

Disclosure Date: March 15, 2023 (last updated October 08, 2023)
A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an administrator, resulting in arbitrary shell code execution. This is fixed in 8.6.1.262 or newer and 10.4.2.93 or newer.
Attacker Value
Unknown

CVE-2023-24613

Disclosure Date: February 03, 2023 (last updated October 08, 2023)
The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite the backend function call stack after accessing the system with administrator privileges. A successful exploit could leverage this vulnerability in the backend binary file that handles the user interface to a cause denial of service attack. This is fixed in AG 9.4.0.481.
Attacker Value
Unknown

CVE-2022-42897

Disclosure Date: October 13, 2022 (last updated October 08, 2023)
Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected.