推文详情
avatar
@screaminggoat@infosec.exchange

CISA: CISA Adds One Known Exploited Vulnerability to Catalog
Hot off the press! CVE-2023-28461 (9.8 critical) Array Networks AG and vxAG ArrayOS Improper Authentication vulnerability

#CVE_2023_28461 #arraynetworks #arrayos #cisa #kev #cisakev #knownexploitedvulnerabilitiescatalog #vulnerability #eitw #activeexploitation #infosec #cybersecurity

查看详情
0
0
0
avatar
@screaminggoat@infosec.exchange

Just a note that CVE-2023-28461 (9.8 critical) Array Networks AG and vxAG ArrayOS Improper Authentication vulnerability, added 25 November 2024 to the KEV Catalog, is known to be used in ransomware campaigns, according to CISA.

EDIT: NEW! Fancy red triangle 🔺when known to be used in ransomware campaigns.

EDIT2: Known to be exploited by the Chinese state actor "Earth Kasha" which may be related to APT10. www.trendmicro.com/...

#CVE_2023_28461 #arraynetworks #ransomware #threatintel #vulnerability #infosec #cve #eitw #activeexploitation #KnownExploitedVulnerabilitiesCatalog #kev #cisa

查看详情
0
0
1
avatar
@wdormann@infosec.exchange

@screaminggoat
The CVE entry, written last week by MITRE, currently states: "a new Array AG release with the fix will be available soon."

The fix was released over 1.5 years ago.

A job done!

查看详情
0
0
0
avatar
@interpipes@thx.gg

@wdormann @screaminggoat confused

the CVE entry (and your screenshot) says it was written/updated 2023-03-15, not last week?

查看详情
0
0
1
@interpipes@thx.gg
0/481
加载中