2.7

CVSS3.1

CVE-2025-4563 - Nodes can bypass dynamic resource allocation authorization checks

A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status updates but fails to pe…

πŸ“… Published: June 19, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 9:26 a.m.

9.8

CVSS3.1

CVE-2025-24288 -

The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

6.1

CVSS3.1

CVE-2025-24291 -

The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allow…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

9.8

CVSS3.1

CVE-2024-45208 -

The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP ports 4566 and 4570 to exchange High Availability (HA) information using a shared password. Affected versions of Versa Director bound to these ports o…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

7.2

CVSS3.1

CVE-2025-23171 -

The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allow file uploads but uploads still succeed. In addition, the Versa Director discloses the full filename …

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

6.3

CVSS3.1

CVE-2025-23168 -

The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA codes, allowing an attacker who knows a valid username and password to redirect the…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: July 9, 2025, 6:23 p.m.

7.2

CVSS3.1

CVE-2025-24286 -

A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: July 16, 2025, 6:54 p.m.

7.2

CVSS3.1

CVE-2025-23172 -

The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This can be leveraged to…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

7.5

CVSS3.1

CVE-2025-23173 -

The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposure introduces significant risk, as websockify has known weakne…

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.

6.1

CVSS3.1

CVE-2025-23169 -

The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious user to inject and store cross-site scripting (XSS) …

πŸ“… Published: June 18, 2025, 11:30 p.m. πŸ”„ Last Modified: June 23, 2025, 8:16 p.m.
Total resulsts: 343194
Page 4358 of 34,320
Β« previous page Β» next page
Filters