Arraynetworks
Arraynetworks Arrayos AG: vulnerabilidades y CVE
Arraynetworks Arrayos AG tiene 6 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 4 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses1
Críticas4
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-66644 | Crítica (9.8) | 3.4% | ⚠ Explotación activa | 5 dic 2025 | Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. |
| CVE-2023-28461 | Crítica (9.8) | 68% | ⚠ Explotación activa | 15 mar 2023 | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication.… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-66644 | Crítica (9.8) | 3.4% | ⚠ Explotación activa | 5 dic 2025 | Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025. |
| CVE-2023-51707 | Crítica (9.8) | 1.3% | — | 22 dic 2023 | MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected. |
| CVE-2023-41121 | Alta (7.5) | 0.84% | — | 25 ago 2023 | Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations. |
| CVE-2023-28461 | Crítica (9.8) | 68% | ⚠ Explotación activa | 15 mar 2023 | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication.… |
| CVE-2023-24613 | Media (4.9) | 0.79% | — | 3 feb 2023 | The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite the backend function call stack after accessing the system with administrator… |
| CVE-2022-42897 | Crítica (9.8) | 1.6% | — | 13 oct 2022 | Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.