Versa / Director
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-24288 | The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most… | CRITICAL | 9.8 | Jun 18, 2025 |
| CVE-2025-24291 | The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains… | MEDIUM | 6.1 | Jun 18, 2025 |
| CVE-2024-45208 | The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP ports 4566… | CRITICAL | 9.8 | Jun 18, 2025 |
| CVE-2025-23171 | The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload p… | HIGH | 7.2 | Jun 18, 2025 |
| CVE-2025-23168 | The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Di… | HIGH | 8.8 | Jun 18, 2025 |
| CVE-2025-23172 | The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" an… | HIGH | 7.2 | Jun 18, 2025 |
| CVE-2025-23173 | The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify… | HIGH | 7.5 | Jun 18, 2025 |
| CVE-2025-23169 | The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provide… | MEDIUM | 6.1 | Jun 18, 2025 |
| CVE-2025-23170 | The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The… | MEDIUM | 6.7 | Jun 18, 2025 |
| CVE-2024-42450 | The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Direct… | CRITICAL | 10.0 | Nov 19, 2024 |
| CVE-2024-45229 | The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registratio… | MEDIUM | 6.6 | Sep 20, 2024 |
| CVE-2024-39717 KEV | The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-D… | HIGH | 7.2 | Aug 22, 2024 |
Showing 1 to 12 of 12 CVEs