Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pj35-hgmm-7fgg

Опубликовано: 16 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

EPSS

Процентиль: 99%
0.87179
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix will be available soon."

EPSS

Процентиль: 99%
0.87179
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306