CVE-2023-28460: Array Networks Array OS

High severity, CVSS 7.2. EPSS: 1.6% chance of exploitation in the next 30 days.

A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted packet after logging into the affected appliance as an administrator, resulting in arbitrary shell code execution. This is fixed in 8.6.1.262 or newer and 10.4.2.93 or newer.

Affected products

  • Array Networks Array OS: up to and including 8.6.1.243; from 9.0.1.12, up to and including 10.4.0.79; from 10.4.2.12, up to and including 10.4.2.58; version 10.4.3.2 only

Published 2023-03-15. Last modified 2026-06-17.