VYPR
High severity7.2NVD Advisory· Published Mar 15, 2023· Updated Jun 17, 2026

CVE-2023-28460

CVE-2023-28460

Description

A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an administrator, resulting in arbitrary shell code execution. This is fixed in 8.6.1.262 or newer and 10.4.2.93 or newer.

Affected products

4
  • Array Networks/APV productsdescription
  • cpe:2.3:o:arraynetworks:array_os:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:arraynetworks:array_os:*:*:*:*:*:*:*:*range: <=8.6.1.243
    • cpe:2.3:o:arraynetworks:array_os:10.4.3.2:*:*:*:*:*:*:*
  • Range: before 8.6.1.262 and before 10.4.2.93

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.