Versa-networks Versa Director — known CVE vulnerabilities
Every CVE whose affected-product data names Versa-networks Versa Director, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (16)
CVE-2024-42450 — CVSS 10.0 (critical): The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function…
CVE-2025-24288 — CVSS 9.8 (critical): The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and…
CVE-2019-25029 — CVSS 9.8 (critical): In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via…
CVE-2025-23173 — CVSS 7.5 (high): The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By…
CVE-2025-23171 — CVSS 7.2 (high): The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly…
CVE-2025-23172 — CVSS 7.2 (high): The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However…
CVE-2025-23170 — CVSS 6.7 (medium): The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via…
CVE-2024-45229 — CVSS 6.6 (medium): The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display…
CVE-2025-23168 — CVSS 6.3 (medium): The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via…
CVE-2025-24291 — CVSS 6.1 (medium): The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling…
CVE-2021-39285 — CVSS 6.1 (medium): A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create…
CVE-2025-23169 — CVSS 6.1 (medium): The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo…
CVE-2019-25030 — CVSS 5.5 (medium): In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation…
CVE-2018-16498 — CVSS 5.5 (medium): In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These…