CVE Feed

    Dashboard / CVE / CVE-2023-28460

    CVE-2023-28460

    A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an administrator, resulting in arbitrary shell code execution. This is fixed in 8.6.1.262 or newer and 10.4.2.93 or newer.

    Published:Mar 15, 2023
    Last Modified:Feb 27, 2025
    EPS:Mar 15, 2023
    EPSS Score:0.00471
    CVSS Score:7.2

    Affected Products

    Vendor
    Arraynetworks
    Product
    Apv10650
    Vendor
    Arraynetworks
    Product
    Apv11600
    Vendor
    Arraynetworks
    Product
    Apv1600
    Vendor
    Arraynetworks
    Product
    Apv1600t
    Vendor
    Arraynetworks
    Product
    Apv1600v5
    Vendor
    Arraynetworks
    Product
    Apv1800
    Vendor
    Arraynetworks
    Product
    Apv2600
    Vendor
    Arraynetworks
    Product
    Apv2600v5
    Vendor
    Arraynetworks
    Product
    Apv2800
    Vendor
    Arraynetworks
    Product
    Apv3600
    Vendor
    Arraynetworks
    Product
    Apv3600v5
    Vendor
    Arraynetworks
    Product
    Apv3650
    Vendor
    Arraynetworks
    Product
    Apv5600
    Vendor
    Arraynetworks
    Product
    Apv5800
    Vendor
    Arraynetworks
    Product
    Apv6600
    Vendor
    Arraynetworks
    Product
    Apv6600fips
    Vendor
    Arraynetworks
    Product
    Apv7600
    Vendor
    Arraynetworks
    Product
    Apv7800
    Vendor
    Arraynetworks
    Product
    Apv800
    Vendor
    Arraynetworks
    Product
    Array Os
    Vendor
    Arraynetworks
    Product
    Vapv

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High