arraynetworks records
7 published records for vendor arraynetworks.
Researcher profile
- Entered KEV
- 2 · 28.6%
- Weaponized
- 2 · 28.6%
- Pre-auth RCE
- 4
- With a fix record
- 14.3%
- Median publish → KEV
- 312 days
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-287 Improper Authentication1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
89Now | CVE-2023-28461Weaponized | Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution.arraynetworks · arrayos ag · CWE-287 | Critical9.8 | KEV | 68.1% | Mar 15, 2023 |
70This week | CVE-2025-66644Weaponized | Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.arraynetworks · arrayos ag · CWE-78 | Critical9.8 | KEV | 3.4% | Dec 5, 2025 |
39Monitor | CVE-2022-42897No exploit | Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and contarraynetworks · arrayos ag · CWE-77 | Critical9.8 | — | 1.6% | Oct 12, 2022 |
39Monitor | CVE-2023-51707No exploit | MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets.arraynetworks · arrayos ag · CWE-77 | Critical9.8 | — | 1.3% | Dec 21, 2023 |
30Monitor | CVE-2023-41121No exploit | Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP oparraynetworks · arrayos ag · CWE-400 | High7.5 | — | 0.8% | Aug 25, 2023 |
28Monitor | CVE-2023-28460No exploit | A command injection vulnerability was discovered in Array Networks APV products.arraynetworks · array os · CWE-77 | High7.2 | — | 1.6% | Mar 15, 2023 |
19Monitor | CVE-2023-24613No exploit | The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite thearraynetworks · arrayos ag · CWE-787 | Medium4.9 | — | 0.8% | Feb 2, 2023 |
- CVE-2023-2846189Now
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 68%arraynetworks · arrayos agMar 15, 2023
- CVE-2025-6664470This week
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
CriticalCVSS 9.8KEVWeaponizedEPSS 3%arraynetworks · arrayos agDec 5, 2025
- CVE-2022-4289739Monitor
Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and cont
CriticalCVSS 9.8No exploitEPSS 2%arraynetworks · arrayos agOct 12, 2022
- CVE-2023-5170739Monitor
MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets.
CriticalCVSS 9.8No exploitEPSS 1%arraynetworks · arrayos agDec 21, 2023
- CVE-2023-4112130Monitor
Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP op
HighCVSS 7.5No exploitEPSS 1%arraynetworks · arrayos agAug 25, 2023
- CVE-2023-2846028Monitor
A command injection vulnerability was discovered in Array Networks APV products.
HighCVSS 7.2No exploitEPSS 2%arraynetworks · array osMar 15, 2023
- CVE-2023-2461319Monitor
The user interface of Array Networks AG Series and vxAG through 9.4.0.470 could allow a remote attacker to use the gdb tool to overwrite the
MediumCVSS 4.9No exploitEPSS 1%arraynetworks · arrayos agFeb 2, 2023