VYPR

Versa Director

by Versa Networks

CVEs (6)

  • CVE-2019-25029CriMay 26, 2021
    risk 0.64cvss 9.8epss 0.03

    In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP…

  • CVE-2024-39717HigKEVAug 22, 2024
    risk 0.59cvss 7.2epss 0.04

    The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change…

  • CVE-2025-23168MedJun 19, 2025
    risk 0.41cvss 6.3epss 0.00

    The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA codes, allowing an attacker who knows a valid username and…

  • CVE-2019-25030MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.00

    In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the Merkle-Damgardconstruction (such as MD5 and SHA-1) alone are insufficient in…

  • CVE-2018-16498MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.00

    In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Trust keystores.

  • CVE-2018-16496MedMay 26, 2021
    risk 0.35cvss 5.3epss 0.01

    In Versa Director, the un-authentication request found.