Versa Director
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-25029 | Cri | 0.64 | 9.8 | 0.03 | May 26, 2021 | In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP… | ||
| CVE-2024-39717 | Hig | 0.59 | 7.2 | 0.04 | KEV | Aug 22, 2024 | The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change… | |
| CVE-2025-23168 | Med | 0.41 | 6.3 | 0.00 | Jun 19, 2025 | The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA codes, allowing an attacker who knows a valid username and… | ||
| CVE-2019-25030 | Med | 0.36 | 5.5 | 0.00 | May 26, 2021 | In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the Merkle-Damgardconstruction (such as MD5 and SHA-1) alone are insufficient in… | ||
| CVE-2018-16498 | Med | 0.36 | 5.5 | 0.00 | May 26, 2021 | In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Trust keystores. | ||
| CVE-2018-16496 | Med | 0.35 | 5.3 | 0.01 | May 26, 2021 | In Versa Director, the un-authentication request found. |
- risk 0.64cvss 9.8epss 0.03
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP…
- risk 0.59cvss 7.2epss 0.04
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change…
- risk 0.41cvss 6.3epss 0.00
The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA codes, allowing an attacker who knows a valid username and…
- risk 0.36cvss 5.5epss 0.00
In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the Merkle-Damgardconstruction (such as MD5 and SHA-1) alone are insufficient in…
- risk 0.36cvss 5.5epss 0.00
In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Trust keystores.
- risk 0.35cvss 5.3epss 0.01
In Versa Director, the un-authentication request found.