Versa-networks

Versa Director

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 18.06.2025 23:30:55
  • Zuletzt bearbeitet 02.09.2026 17:35:34

The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director ex...

  • EPSS 0.35%
  • Veröffentlicht 18.06.2025 23:30:54
  • Zuletzt bearbeitet 08.09.2026 19:29:43

The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, a...

  • EPSS 0.5%
  • Veröffentlicht 18.06.2025 23:30:53
  • Zuletzt bearbeitet 25.08.2026 14:26:38

The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allow file uploads but uploads still succeed. In addition...

  • EPSS 0.36%
  • Veröffentlicht 18.06.2025 23:30:52
  • Zuletzt bearbeitet 09.07.2025 18:23:33

The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA codes, allowing an attacker who kn...

  • EPSS 0.99%
  • Veröffentlicht 18.06.2025 23:30:51
  • Zuletzt bearbeitet 03.09.2026 18:22:02

The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTT...

  • EPSS 0.53%
  • Veröffentlicht 18.06.2025 23:30:50
  • Zuletzt bearbeitet 08.09.2026 19:29:38

The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposure introduces...

  • EPSS 0.34%
  • Veröffentlicht 18.06.2025 23:30:49
  • Zuletzt bearbeitet 03.09.2026 18:22:12

The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious use...

  • EPSS 0.62%
  • Veröffentlicht 18.06.2025 23:30:49
  • Zuletzt bearbeitet 03.09.2026 18:21:59

The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the ...

  • EPSS 0.56%
  • Veröffentlicht 19.11.2024 18:15:20
  • Zuletzt bearbeitet 03.09.2026 18:22:14

The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Versa Director....

  • EPSS 0.51%
  • Veröffentlicht 20.09.2024 19:15:16
  • Zuletzt bearbeitet 25.08.2026 14:28:04

The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly co...