Versa-networks
Versa-networks Versa Director: vulnerabilidades y CVE
Versa-networks Versa Director tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas4
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-39717 | Alta (7.2) | 4.0% | ⚠ Explotación activa | 22 ago 2024 | The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin.… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-24291 | Media (6.1) | 0.38% | — | 19 jun 2025 | The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending… |
| CVE-2025-24288 | Crítica (9.8) | 0.47% | — | 19 jun 2025 | The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default… |
| CVE-2025-23173 | Alta (7.5) | 0.62% | — | 19 jun 2025 | The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the… |
| CVE-2025-23172 | Alta (7.2) | 1.1% | — | 19 jun 2025 | The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an… |
| CVE-2025-23171 | Alta (7.2) | 0.55% | — | 19 jun 2025 | The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allow file uploads but… |
| CVE-2025-23170 | Media (6.7) | 0.59% | — | 19 jun 2025 | The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to… |
| CVE-2025-23169 | Media (6.1) | 0.38% | — | 19 jun 2025 | The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or… |
| CVE-2025-23168 | Alta (8.8) | 0.40% | — | 19 jun 2025 | The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA… |
| CVE-2024-45208 | Crítica (9.8) | 0.86% | — | 19 jun 2025 | The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP ports 4566 and 4570 to exchange High Availability (HA) information… |
| CVE-2024-42450 | Crítica (10) | 0.58% | — | 19 nov 2024 | The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across… |
| CVE-2024-45229 | Media (6.6) | 0.51% | — | 20 sept 2024 | The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered… |
| CVE-2024-39717 | Alta (7.2) | 4.0% | ⚠ Explotación activa | 22 ago 2024 | The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin.… |
| CVE-2021-39285 | Media (6.1) | 0.78% | — | 7 sept 2021 | A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack. |
| CVE-2019-25030 | Media (5.5) | 0.22% | — | 26 may 2021 | In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the… |
| CVE-2019-25029 | Crítica (9.8) | 2.4% | — | 26 may 2021 | In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an… |
| CVE-2018-16498 | Media (5.5) | 0.17% | — | 26 may 2021 | In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and… |
| CVE-2018-16496 | Media (5.3) | 0.74% | — | 26 may 2021 | In Versa Director, the un-authentication request found. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.