VYPR

Array AG OS

by Array Networks

CVEs (3)

  • CVE-2022-42897CriOct 13, 2022
    risk 0.64cvss 9.8epss 0.02

    Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected.

  • CVE-2025-66644HigKEVDec 5, 2025
    risk 0.59cvss 7.2epss 0.03

    Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

  • CVE-2023-41121HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations.