Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.38% | — | Versa-networks Versa Director | 19/6/2025 | 8/9/2026 | The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of… | |
| Analizada | Crítica (9.8) | 0.47% | — | Versa-networks Versa Director | 19/6/2025 | 2/9/2026 | The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside a host of other… | |
| Analizada | Alta (7.5) | 0.62% | — | Versa-networks Versa Director | 19/6/2025 | 8/9/2026 | The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposure introduces significant risk, as websockify has known weaknesses that can be… | |
| Analizada | Alta (7.2) | 1.1% | — | Versa-networks Versa Director | 19/6/2025 | 3/9/2026 | The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This can be leveraged to execute commands on… | |
| Analizada | Alta (7.2) | 0.55% | — | Versa-networks Versa Director | 19/6/2025 | 25/8/2026 | The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allow file uploads but uploads still succeed. In addition, the Versa Director discloses the full filename of uploaded… | |
| Analizada | Media (6.7) | 0.59% | — | Versa-networks Versa Director | 19/6/2025 | 3/9/2026 | The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an attacker to execute arbitrary commands… | |
| Analizada | Media (6.1) | 0.38% | — | Versa-networks Versa Director | 19/6/2025 | 3/9/2026 | The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious user to inject and store cross-site scripting (XSS) payloads.… | |
| Analizada | Alta (8.8) | 0.40% | — | Versa-networks Versa Director | 19/6/2025 | 17/6/2026 | The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA codes, allowing an attacker who knows a valid username and password to redirect the OTP delivery… | |
| Aplazada | Crítica (9.8) | 0.86% | — | Cisco NCSAIVersa-networks Versa DirectorAI | 19/6/2025 | 17/6/2026 | The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP ports 4566 and 4570 to exchange High Availability (HA) information using a shared password. Affected versions of Versa Director bound to these ports on all interfaces. An… | |
| Analizada | Crítica (10) | 0.58% | — | Versa-networks Versa Director | 19/11/2024 | 3/9/2026 | The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Versa Director. By default, Versa Director configures Postgres to listen on all… | |
| Analizada | Media (6.6) | 0.51% | — | Versa-networks Versa Director | 20/9/2024 | 25/8/2026 | The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one of these APIs can be exploited by… | |
| Analizada | Alta (7.2) | 4.0% | ⚠ Explotación activa | Versa-networks Versa Director | 22/8/2024 | 17/6/2026 | The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be… | |
| Modificada | Media (6.1) | 0.78% | — | Versa-networks Versa Director | 7/9/2021 | 17/6/2026 | A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack. | |
| Modificada | Media (5.5) | 0.22% | — | Versa-networks Versa AnalyticsVersa-networks Versa DirectorVersa-networks Versa Operating System | 26/5/2021 | 17/6/2026 | In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the Merkle-Damgardconstruction (such as MD5 and SHA-1) alone are insufficient in thwarting password cracking. Attackers can… | |
| Analizada | Crítica (9.8) | 2.4% | — | Versa-networks Versa Director | 26/5/2021 | 31/8/2026 | In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In… | |
| Modificada | Media (5.5) | 0.17% | — | Versa-networks Versa Director | 26/5/2021 | 17/6/2026 | In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Trust keystores. | |
| Modificada | Media (5.3) | 0.74% | — | Versa-networks Versa Director | 26/5/2021 | 17/6/2026 | In Versa Director, the un-authentication request found. |