#VU100948 Improper Authentication in ArrayOS - CVE-2023-28461
Published: November 26, 2024
ArrayOS
Array Networks
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the authentication process. A remote non-authenticated attacker can bypass authentication process using a specially crafted URL and gain unauthorized access to the SSL-VPN device.
Remediation
The vulnerability affects ArrayOS AG/vxAG devices 9.4.0.481 and earlier.
To resolve the vulnerability update to the latest version.