7.2

CVE-2023-28460

A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an administrator, resulting in arbitrary shell code execution. This is fixed in 8.6.1.262 or newer and 10.4.2.93 or newer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ArraynetworksArray Os Version <= 8.6.1.243
   ArraynetworksApv10650 Version-
   ArraynetworksApv11600 Version-
   ArraynetworksApv1600 Version-
   ArraynetworksApv1600t Version-
   ArraynetworksApv1600v5 Version-
   ArraynetworksApv1800 Version-
   ArraynetworksApv2600 Version-
   ArraynetworksApv2600v5 Version-
   ArraynetworksApv2800 Version-
   ArraynetworksApv3600 Version-
   ArraynetworksApv3600v5 Version-
   ArraynetworksApv3650 Version-
   ArraynetworksApv5600 Version-
   ArraynetworksApv5800 Version-
   ArraynetworksApv6600 Version-
   ArraynetworksApv6600fips Version-
   ArraynetworksApv7600 Version-
   ArraynetworksApv7800 Version-
   ArraynetworksApv800 Version-
   ArraynetworksVapv Version-
ArraynetworksArray Os Version >= 9.0.1.12 <= 10.4.0.79
   ArraynetworksApv10650 Version-
   ArraynetworksApv11600 Version-
   ArraynetworksApv1600 Version-
   ArraynetworksApv1600t Version-
   ArraynetworksApv1600v5 Version-
   ArraynetworksApv1800 Version-
   ArraynetworksApv2600 Version-
   ArraynetworksApv2600v5 Version-
   ArraynetworksApv2800 Version-
   ArraynetworksApv3600 Version-
   ArraynetworksApv3600v5 Version-
   ArraynetworksApv3650 Version-
   ArraynetworksApv5600 Version-
   ArraynetworksApv5800 Version-
   ArraynetworksApv6600 Version-
   ArraynetworksApv6600fips Version-
   ArraynetworksApv7600 Version-
   ArraynetworksApv7800 Version-
   ArraynetworksApv800 Version-
   ArraynetworksVapv Version-
ArraynetworksArray Os Version >= 10.4.2.12 <= 10.4.2.58
   ArraynetworksApv10650 Version-
   ArraynetworksApv11600 Version-
   ArraynetworksApv1600 Version-
   ArraynetworksApv1600t Version-
   ArraynetworksApv1600v5 Version-
   ArraynetworksApv1800 Version-
   ArraynetworksApv2600 Version-
   ArraynetworksApv2600v5 Version-
   ArraynetworksApv2800 Version-
   ArraynetworksApv3600 Version-
   ArraynetworksApv3600v5 Version-
   ArraynetworksApv3650 Version-
   ArraynetworksApv5600 Version-
   ArraynetworksApv5800 Version-
   ArraynetworksApv6600 Version-
   ArraynetworksApv6600fips Version-
   ArraynetworksApv7600 Version-
   ArraynetworksApv7800 Version-
   ArraynetworksApv800 Version-
   ArraynetworksVapv Version-
ArraynetworksArray Os Version10.4.3.2
   ArraynetworksApv10650 Version-
   ArraynetworksApv11600 Version-
   ArraynetworksApv1600 Version-
   ArraynetworksApv1600t Version-
   ArraynetworksApv1600v5 Version-
   ArraynetworksApv1800 Version-
   ArraynetworksApv2600 Version-
   ArraynetworksApv2600v5 Version-
   ArraynetworksApv2800 Version-
   ArraynetworksApv3600 Version-
   ArraynetworksApv3600v5 Version-
   ArraynetworksApv3650 Version-
   ArraynetworksApv5600 Version-
   ArraynetworksApv5800 Version-
   ArraynetworksApv6600 Version-
   ArraynetworksApv6600fips Version-
   ArraynetworksApv7600 Version-
   ArraynetworksApv7800 Version-
   ArraynetworksApv800 Version-
   ArraynetworksVapv Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.711
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.