A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an administrator, resulting in arbitrary shell code execution. This is fixed in 8.6.1.262 or newer and 10.4.2.93 or newer.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Arraynetworks
Subscribe
|
Apv10650
Subscribe
Apv11600
Subscribe
Apv1600
Subscribe
Apv1600t
Subscribe
Apv1600v5
Subscribe
Apv1800
Subscribe
Apv2600
Subscribe
Apv2600v5
Subscribe
Apv2800
Subscribe
Apv3600
Subscribe
Apv3600v5
Subscribe
Apv3650
Subscribe
Apv5600
Subscribe
Apv5800
Subscribe
Apv6600
Subscribe
Apv6600fips
Subscribe
Apv7600
Subscribe
Apv7800
Subscribe
Apv800
Subscribe
Array Os
Subscribe
Vapv
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32139 | A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an administrator, resulting in arbitrary shell code execution. This is fixed in 8.6.1.262 or newer and 10.4.2.93 or newer. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-27T14:18:37.236Z
Reserved: 2023-03-15T00:00:00.000Z
Link: CVE-2023-28460
Updated: 2024-08-02T12:38:25.363Z
Status : Modified
Published: 2023-03-15T23:15:10.013
Modified: 2024-11-21T07:55:07.767
Link: CVE-2023-28460
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD