HomeSecurityCISA adds Array Networks vulnerability to KEV List

CISA adds Array Networks vulnerability to KEV List

The U.S. Cybersecurity and Infrastructure Security Agency ( CISA ) has added a critical vulnerability affecting Array Networks AG and vxAG secure access gateways to its list of Known Exploitable Vulnerabilities (KEV).

CISA KEV Array Networks Catalog

The vulnerability is tracked as CVE-2023-28461 (CVSS score: 9.8) and is related to incomplete authentication that could be used to execute malicious code remotely. The vulnerability has been patched (version 9.4.0.484) since March 2023, but according to CISA it is being used in attacks.

See also: QNAP fixed critical vulnerabilities in various products

In fact, cybersecurity firm Trend Micro recently revealed that Chinese hackers Earth Kasha are exploiting vulnerabilities in products such as Array AG (CVE-2023-28461), Proself (CVE-2023-45727), and Fortinet FortiOS/FortiProxy (CVE-2023-27997) to gain initial access to systems.

Due to the exploit, Federal Civilian Executive Branch (FCEB) agencies are advised to apply the updates by December 16, 2024 .

While CISA's KEV list is primarily designed to alert federal agencies, all organizations should prioritize patching these vulnerabilities.

See also: XSS vulnerability in Bing allows malicious requests

The KEV catalog is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.

CISA adds Array Networks vulnerability to KEV List

Overall, CISA is a great help in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, governments , and local authorities, to improve the security of digital systems.

It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.

See also: NVIDIA Base Command Manager vulnerability allows remote code execution

Overall, CISA's role is vital to protecting the digital infrastructure of the US and other regions.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS