CISA | Alerts
Follow
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has updated its Known Exploited Vulnerabilities Catalog with a new vulnerability, CVE-2023-28461, which affects Array Networks AG and vxAG ArrayOS due to improper authentication. This vulnerability is a common attack vector for malicious actors and poses a significant risk to the federal enterprise. The Known Exploited Vulnerabilities Catalog was established by Binding Operational Directive (BOD) 22-01 to address vulnerabilities that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the specified due date to protect their networks against active threats. CISA strongly urges all organizations to prioritize timely remediation of catalog vulnerabilities as part of their vulnerability management practice. The catalog will continue to be updated with vulnerabilities that meet the specified criteria. The BOD 22-01 Fact Sheet provides more information on the directive. FCEB agencies must comply with BOD 22-01 to protect their networks. Non-FCEB organizations should also take steps to mitigate these vulnerabilities to enhance their cybersecurity posture.