9.8

CVSS3.1

CVE-2025-24288 -

The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

6.1

CVSS3.1

CVE-2025-24291 -

The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allow…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

9.8

CVSS3.1

CVE-2024-45208 -

The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP ports 4566 and 4570 to exchange High Availability (HA) information using a shared password. Affected versions of Versa Director bound to these ports o…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

7.2

CVSS3.1

CVE-2025-23171 -

The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allow file uploads but uploads still succeed. In addition, the Versa Director discloses the full filename …

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

6.3

CVSS3.1

CVE-2025-23168 -

The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA codes, allowing an attacker who knows a valid username and password to redirect the…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: July 9, 2025, 6:23 p.m.

7.2

CVSS3.1

CVE-2025-24286 -

A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: July 16, 2025, 6:54 p.m.

7.2

CVSS3.1

CVE-2025-23172 -

The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This can be leveraged to…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

7.5

CVSS3.1

CVE-2025-23173 -

The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposure introduces significant risk, as websockify has known weakne…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

6.1

CVSS3.1

CVE-2025-23169 -

The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious user to inject and store cross-site scripting (XSS) …

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

6.7

CVSS3.1

CVE-2025-23170 -

The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an attacker to execute…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.
Total resulsts: 343183
Page 4357 of 34,319
Β« previous page Β» next page
Filters