CVE Tools

Versa

9 CVEs tracked since 2025. Since Jun 2025, none of them reached CISA KEV.

Versa CVEs per month

Jun 2025 to Jun 2025. Point at a month, or focus the strip and use the arrow keys.
Versa CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-0690

Products

The products that kept showing up in Versa's monthly top three, with their CVEs summed over those months.

  1. Director91 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Versa.

  1. CVE-2025-24288The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the sa...9.8
  2. CVE-2025-24291The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. ...6.1
  3. CVE-2025-23171The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allo...7.2
  4. CVE-2024-45208The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP ports 4566 and 4570 to exchange High Availabilit...9.8
  5. CVE-2025-23168The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input wh...6.3
  6. CVE-2025-23172The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can b...7.2
  7. CVE-2025-23173The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and a...7.5
  8. CVE-2025-23169The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not prop...6.1
  9. CVE-2025-23170The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connec...6.7
  10. CVE-2025-34025Versa Concerto Insecure Docker Mount Container Escape8.8
  11. CVE-2025-34026Versa Concerto Actuator Authentication Bypass Information Leak7.5
  12. CVE-2025-34027Versa Concerto Authentication Bypass File Write Remote Code Execution9.0
  13. CVE-2024-42450The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a co...10.0
  14. CVE-2024-45229The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. Howe...6.6
  15. CVE-2024-39717The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Cent...7.2

The record

Peak rank
#90 in Jun 2025
Busiest month shown
Jun 2025, 9 CVEs
Months with a KEV entry
0 since Jun 2025
Monthly snapshots
1 since 2025
Versa's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store